MD-101 Managing Modern Desktops (MD-101) v1.0 5 — Questions and Answers
Question 1: Which Microsoft Intune report shows the number of devices that have successfully installed a specific Windows update?
- Device compliance report
- Windows feature update report (Correct answer)
- Endpoint analytics baseline report
- App install status report
Correct answer: Windows feature update report
The Windows feature update report in Intune shows installation status and counts for each Windows feature update across managed devices.
Question 2: A user on a shared Windows 11 kiosk device should only be able to run one specific UWP application. Which Intune configuration should you apply?
- Device restrictions – General
- Kiosk mode – Single app kiosk (Correct answer)
- App protection policy
- Assigned Access via PowerShell
Correct answer: Kiosk mode – Single app kiosk
Single app kiosk mode in Intune locks the device to run only one specified UWP or Microsoft Edge app for a designated user or account.
Question 3: Which Azure AD feature automatically marks a sign-in as risky when it detects unusual travel or anonymous IP usage?
- Azure AD Smart Lockout
- Azure AD Identity Protection (Correct answer)
- Azure AD Conditional Access named locations
- Multi-Factor Authentication
Correct answer: Azure AD Identity Protection
Azure AD Identity Protection uses machine learning to detect risky sign-ins and can block or require MFA based on detected risk levels.
Question 4: A Windows 10 device fails to enroll in Intune with error 0x80180014. What is the most likely cause?
- The device already has an MDM enrollment from another provider
- BitLocker must be enabled first
- The user account lacks an Intune license (Correct answer)
- The device is not Azure AD joined
Correct answer: The user account lacks an Intune license
Error 0x80180014 typically indicates the user does not have an Intune license assigned, preventing enrollment.
Question 5: You want to collect and analyze device health and startup performance data across your managed Windows fleet. Which Microsoft service provides this?
- Microsoft Defender for Endpoint
- Endpoint Analytics (in Microsoft Intune) (Correct answer)
- Windows Analytics (deprecated)
- Azure Monitor Logs
Correct answer: Endpoint Analytics (in Microsoft Intune)
Endpoint Analytics in Microsoft Intune provides insights into device startup performance, application reliability, and recommended software.
Question 6: Which policy setting in an Intune Windows device configuration profile prevents users from changing the time zone on their device?
- Device restrictions – Control Panel and Settings (Correct answer)
- Device restrictions – General – Time zone
- Endpoint security – Firewall
- Administrative templates – User Rights Assignment
Correct answer: Device restrictions – Control Panel and Settings
The Device restrictions – Control Panel and Settings section allows administrators to block users from accessing time/date settings.
Question 7: An organization is migrating from co-management to full Intune management. Which workload must be switched to Intune LAST to avoid breaking device management continuity?
- Compliance policies
- Windows Update policies
- Device configuration (Correct answer)
- Endpoint protection
Correct answer: Device configuration
Device configuration workload should be switched last because it controls the broadest range of settings; switching it prematurely can disrupt device management.
Which Microsoft Intune report shows the number of devices that have successfully installed a specific Windows update?