MD-102 Exam β Questions and Answers
Question 1: Which enrollment method allows employees to enroll their personal Android devices while keeping personal and work data separate?
- Android Enterprise personally-owned work profile (Correct answer)
- Android device administrator
- Android Enterprise fully managed
- Android Enterprise dedicated device
Correct answer: Android Enterprise personally-owned work profile
Android Enterprise personally-owned work profile enrollment creates a separate encrypted work container on personal devices, keeping corporate and personal data isolated.
Question 2: An admin configured an app protection policy for Android but users can still copy corporate data to personal apps. What is the most likely cause?
- The app is not an Intune-managed app (SDK integrated or wrapped) (Correct answer)
- The assignment group is incorrect
- The app is not enrolled in Intune
- The device is not compliant
Correct answer: The app is not an Intune-managed app (SDK integrated or wrapped)
App protection policies only control data transfer for apps that include the Intune SDK or have been wrapped with the Intune App Wrapping Tool; unsupported apps are unaffected.
Question 3: A user needs to sign in to Windows 10 using Windows Hello for Business. Which authentication method does Windows Hello for Business replace?
- RADIUS authentication
- Password-based authentication (Correct answer)
- Smart card authentication
- Certificate-based authentication
Correct answer: Password-based authentication
Windows Hello for Business replaces password-based authentication with strong two-factor authentication using a PIN or biometric tied to a device-bound credential.
Question 4: An administrator needs to check which Windows updates are installed on a specific managed device from the Intune portal. Where should they look?
- Devices > Select device > Monitor > Windows update installations (Correct answer)
- Reports > Endpoint analytics > Device performance
- Devices > Monitor > Windows Update > Feature update failures
- Devices > Device compliance
Correct answer: Devices > Select device > Monitor > Windows update installations
In Intune, navigating to a specific device and selecting Monitor then Windows update installations shows the update history for that device, including installed updates and any failures.
Question 5: Which Microsoft store integration model is recommended for deploying Microsoft Store apps in Intune for Windows 11 devices?
- MSIX package
- Sideloading
- Microsoft Store app (new) (Correct answer)
- Windows Store for Business (Legacy)
Correct answer: Microsoft Store app (new)
The new Microsoft Store app integration in Intune supports WinGet-based deployment and is the recommended model for deploying Store apps on Windows 11 devices.
Question 6: A Windows 10 device is Azure AD joined. A user wants to use Windows Hello for Business. What is required for cloud-only deployments?
- Active Directory Certificate Services
- Active Directory Federation Services
- Azure AD Premium P1 license (Correct answer)
- On-premises PKI infrastructure
Correct answer: Azure AD Premium P1 license
Windows Hello for Business cloud-only deployments require Azure AD Premium P1 to support the certificate trust or key trust models.
Question 7: Which Azure AD feature allows users to register their Windows 10 devices so they can access organizational resources with a personal device?
- Azure AD Registered (Correct answer)
- Workplace Join
- Azure AD Join
- Hybrid Azure AD Join
Correct answer: Azure AD Registered
Azure AD Registered is designed for personal (BYOD) devices that users register to access organizational resources without the device being fully joined to Azure AD.
Question 8: Which app protection policy setting prevents users from taking screenshots of corporate data in managed apps on Android?
- Block screen capture and Android Assistant (Correct answer)
- Restrict cut, copy, and paste
- Save copies of org data
- Require PIN for access
Correct answer: Block screen capture and Android Assistant
The 'Block screen capture and Android Assistant' setting in Intune app protection policies prevents screenshots of corporate app content on Android devices.
Question 9: Which Windows ADK component is required for creating bootable WinPE media used during OS deployment?
- Windows Performance Toolkit
- User State Migration Tool (USMT)
- Windows Preinstallation Environment (WinPE) add-on (Correct answer)
- Application Compatibility Toolkit
Correct answer: Windows Preinstallation Environment (WinPE) add-on
The Windows PE add-on for the Windows ADK provides the tools needed to create bootable WinPE media used during OS deployment tasks.
Question 10: A company needs to ensure sensitive files on Windows 10 are encrypted and access is restricted to corporate apps only. Which feature should be configured?
- Windows Information Protection (WIP) (Correct answer)
- BitLocker
- Conditional Access
- Azure Information Protection
Correct answer: Windows Information Protection (WIP)
Windows Information Protection (WIP) encrypts corporate data and restricts access to designated enterprise apps, protecting data without interfering with personal data.
Question 11: An organization uses Hybrid Azure AD Join. What tool is used to synchronize on-premises AD accounts to Azure AD?
- Azure AD Connect (Correct answer)
- ADFS Proxy
- Azure AD App Proxy
- Active Directory Migration Tool
Correct answer: Azure AD Connect
Azure AD Connect is the Microsoft tool that synchronizes on-premises Active Directory identities, including device objects, to Azure AD.
Question 12: An organisation wants to deploy Windows to new devices without physical media, ensuring Azure AD join and Intune enrollment automatically. Which solution is best?
- SCCM OSD Task Sequence
- Windows Deployment Services (WDS)
- Windows Autopilot (Correct answer)
- MDT with PXE boot
Correct answer: Windows Autopilot
Windows Autopilot enables zero-touch deployment where devices are automatically configured, Azure AD-joined, and Intune-enrolled out of the box without physical media or on-premises infrastructure.
Question 13: Which Windows Autopilot deployment mode allows a technician to pre-configure a device before handing it to the end user?
- User-driven mode
- Self-deploying mode
- Pre-provisioning (white glove) mode (Correct answer)
- Reset mode
Correct answer: Pre-provisioning (white glove) mode
Pre-provisioning (white glove) mode allows IT staff or partners to complete the Autopilot provisioning process on behalf of the user so the device is fully configured before reaching the end user.
Question 14: Which Azure AD role has the least privilege to manage Intune device compliance policies?
- Security Administrator
- Intune Administrator (Correct answer)
- Global Administrator
- Compliance Administrator
Correct answer: Intune Administrator
The Intune Administrator role provides the necessary permissions to manage device compliance policies without granting full Global Administrator access.
Question 15: Which Microsoft service provides a centralized security dashboard that aggregates alerts from Defender for Endpoint, Intune compliance, and identity risk?
- Microsoft 365 Defender portal (Correct answer)
- Microsoft Intune admin center
- Azure Security Center
- Microsoft Compliance Manager
Correct answer: Microsoft 365 Defender portal
The Microsoft 365 Defender portal (security.microsoft.com) aggregates security signals from Defender for Endpoint, Defender for Identity, and other services into a unified security dashboard.
Question 16: An administrator needs to remotely remove all corporate data from a user Windows device while leaving personal data intact. Which Intune action achieves this?
- Fresh Start
- Delete
- Wipe (full factory reset)
- Retire (Correct answer)
Correct answer: Retire
The Retire action in Intune removes corporate-managed apps, policies, and data from a device while leaving personal data and settings intact, making it suitable for BYOD offboarding.
Question 17: Which Windows Update for Business policy type controls when quality updates (monthly cumulative updates) are installed on managed devices?
- Feature update policy
- Quality update policy via Update ring (Correct answer)
- Driver update policy
- Expedite update policy
Correct answer: Quality update policy via Update ring
Update rings in Windows Update for Business define deferral periods and deadlines for quality updates, controlling when monthly cumulative updates are installed on groups of devices.
Question 18: Which Windows Autopilot deployment mode allows IT to pre-provision a device so it is fully configured before being handed to the end user?
- Pre-provisioning mode (Correct answer)
- User-driven mode
- Self-deploying mode
- Hybrid join mode
Correct answer: Pre-provisioning mode
Pre-provisioning mode (White Glove) allows IT or a partner to complete most of the Autopilot setup before the device reaches the end user.
Question 19: Which Intune policy can prevent users from modifying Microsoft Defender Antivirus settings on their Windows 10 devices?
- Tamper protection setting in Antivirus policy (Correct answer)
- Endpoint security baseline
- Device restriction configuration profile
- App protection policy
Correct answer: Tamper protection setting in Antivirus policy
Tamper protection, configured through the Intune Antivirus policy, prevents users and malware from modifying Microsoft Defender Antivirus security settings.
Question 20: Your network contains an Active Directory domain named contoso.com. The domain contains 25 computers that run Windows 11. You have a Microsoft 365 subscription You have an Azure AD tenant that syncs with contoso.com. You configure hybrid Azure AD join and discover that some of the computers have a registered state of Pending. You need to ensure that the computers complete the join successfully. <br> What should you ensure?
- that the computers contain the latest quality updates
- that each computer has a line of sight to a domain controller (Correct answer)
- that Windows is activated on all the computers
- that the users of the computers are assigned Microsoft 365 licenses
Correct answer: that each computer has a line of sight to a domain controller
For hybrid Azure AD join to complete successfully, the computers need to be able to communicate directly with an on-premises Active Directory domain controller. This 'line of sight' is crucial for the device registration process, as the domain controller is responsible for syncing the device object to Azure AD. Without this connectivity, the device registration can remain in a 'Pending' state.
Question 21: What prerequisite must be configured before Windows devices can use Delivery Optimization for peer-to-peer update sharing on the same local network?
- Devices must be on the same subnet or have DOGroupID configured (Correct answer)
- Windows Update for Business must be configured
- Azure AD join is required
- A WSUS server must be present on the network
Correct answer: Devices must be on the same subnet or have DOGroupID configured
For Delivery Optimization peer sharing, devices must be on the same subnet by default, or the DOGroupID policy must be configured to group devices across subnets for content sharing.
Question 22: What does the Enrollment Status Page (ESP) do during Windows Autopilot deployment?
- It sends an email notification when enrollment is complete
- It records the device in the Autopilot hardware hash database
- It blocks the user from accessing the desktop until required apps and policies are applied (Correct answer)
- It captures diagnostic logs and uploads them to Intune
Correct answer: It blocks the user from accessing the desktop until required apps and policies are applied
The Enrollment Status Page prevents the user from accessing the desktop or apps until all required configurations, applications, and policies have been successfully applied to the device.
Question 23: An administrator needs to ensure that only compliant devices can access Microsoft 365 resources. Which Azure AD feature should be configured?
- Conditional Access (Correct answer)
- Privileged Identity Management
- Identity Protection
- Access Reviews
Correct answer: Conditional Access
Conditional Access policies in Azure AD can enforce that only devices marked compliant by Intune are permitted to access Microsoft 365 resources.
Question 24: Which Intune app configuration policy delivery channel is used to configure settings for managed apps on enrolled devices?
- MAM without enrollment
- Managed apps channel
- Managed devices channel (Correct answer)
- App protection policy
Correct answer: Managed devices channel
App configuration policies for managed devices deliver configuration settings through the MDM channel to apps installed on enrolled Intune-managed devices.
Question 25: Which feature in Microsoft Endpoint Manager provides insights into device performance metrics like startup times and application reliability scores?
- Windows Update for Business reports
- Device compliance reports
- Endpoint analytics (Correct answer)
- Microsoft Defender reports
Correct answer: Endpoint analytics
Endpoint analytics in Microsoft Endpoint Manager collects performance data and provides insights such as startup performance scores and application reliability to help identify problematic devices.
Question 26: An administrator wants to test feature updates on a pilot group before deploying to all users. Which Intune feature enables this staged deployment approach?
- Feature update deployments (Correct answer)
- Windows Autopatch
- Compliance policies
- Update rings
Correct answer: Feature update deployments
Feature update deployments in Intune allow administrators to target specific Windows feature update versions to designated device groups for controlled rollout.
Question 27: What is the minimum requirement for a device to be eligible for Windows Autopilot deployment?
- The device hardware hash must be registered in Intune or Autopilot (Correct answer)
- The device must have Windows 10 Pro or higher installed
- The device must have a TPM 2.0 chip
- The device must be domain-joined
Correct answer: The device hardware hash must be registered in Intune or Autopilot
For Autopilot to recognise and configure a device automatically, its hardware hash must be registered in Microsoft Intune or the Autopilot deployment service.
Question 28: Which Microsoft service automates Windows quality and feature update management for Microsoft 365 E3/E5 licensed devices with a 'test, deploy, monitor, respond' lifecycle?
- Windows Update for Business
- Microsoft Intune Suite
- Microsoft Endpoint Manager
- Windows Autopatch (Correct answer)
Correct answer: Windows Autopatch
Windows Autopatch is a cloud service included with Windows E3/E5 that automates the entire update management lifecycle, including testing, staged deployment, monitoring, and rollback if issues are detected.
Question 29: Which protocol does Windows Hello for Business use for authentication in a key trust deployment?
- OAuth 2.0
- NTLM
- Kerberos (Correct answer)
- SAML
Correct answer: Kerberos
Windows Hello for Business key trust uses Kerberos for on-premises authentication by leveraging the user's key credential registered in AD.
Question 30: An organisation wants to ensure that only devices with a specific minimum OS version can access corporate email. Which combination of Intune features achieves this?
- Device configuration profile and App protection policy
- Device compliance policy with OS version requirement and Conditional Access policy (Correct answer)
- Endpoint security policy and Windows Update ring
- SCEP certificate profile and Wi-Fi configuration profile
Correct answer: Device compliance policy with OS version requirement and Conditional Access policy
A device compliance policy defines the minimum OS version requirement and a Conditional Access policy grants email access only to compliant devices, blocking devices running older OS versions.
Question 31: Which Intune app deployment type should be used to deploy a line-of-business (LOB) Win32 application to Windows 10 devices?
- Web link
- Windows app (Win32)
- Microsoft Store app
- Win32 app (IntuneWin package) (Correct answer)
Correct answer: Win32 app (IntuneWin package)
Win32 LOB apps are packaged using the Microsoft Win32 Content Prep Tool into an .intunewin file and deployed as a Win32 app type in Intune.
Question 32: What tool can be used to extract and upload Windows hardware hashes to Autopilot in bulk?
- Windows Configuration Designer
- Microsoft Endpoint Configuration Manager
- Microsoft Deployment Toolkit
- Get-WindowsAutoPilotInfo PowerShell script (Correct answer)
Correct answer: Get-WindowsAutoPilotInfo PowerShell script
The Get-WindowsAutoPilotInfo PowerShell script captures hardware hash information from devices and can upload it directly to Windows Autopilot.
Question 33: Which action in Intune allows an administrator to remove corporate data from a device while leaving personal data intact?
- Fresh start
- Delete
- Factory reset (wipe)
- Retire (Correct answer)
Correct answer: Retire
The Retire action in Intune removes only corporate-managed data, apps, and configuration from a device, preserving the user's personal data and apps.
Question 34: You have a Microsoft 365 subscription that includes Microsoft Intune. The subscription contains corporate-owned, fully managed Android Enterprise devices. You plan to deploy a configuration profile that will have a device restrictions profile type named Profile1. Profile1 will assign maintenance windows for system updates. <br> What should you configure from the Configuration settings for Profile1?
- General
- Device experience (Correct answer)
- Connectivity
- Power Settings Explanation
Correct answer: Device experience
For Android Enterprise corporate-owned, fully managed devices, settings related to system updates, including defining maintenance windows, are found under the "Device experience" category within a device restrictions configuration profile. This section allows administrators to control various aspects of the device's user experience and operational behavior, such as update policies, kiosk modes, and display settings.
Question 35: Which Azure AD feature can automatically detect risky sign-in events and prompt for MFA or block access based on a risk score?
- Privileged Identity Management
- Conditional Access
- Identity Protection (Correct answer)
- Access Reviews
Correct answer: Identity Protection
Azure AD Identity Protection evaluates sign-in risk using machine learning and can automatically enforce MFA or block access based on the detected risk level.
Question 36: Which license is required to use Azure AD Privileged Identity Management (PIM)?
- Azure AD Premium P2 (Correct answer)
- Azure AD Free
- Microsoft 365 Business Basic
- Azure AD Premium P1
Correct answer: Azure AD Premium P2
Azure AD Privileged Identity Management requires Azure AD Premium P2 licenses to provide just-in-time privileged access management.
Question 37: Which of the following statements NOT true about policy sets?
- The default restrictions and ESP cannot be added to a policy set
- It can be assigned as cross-platform
- Used for group objects that need to be assigned together
- Policy sets will replace existing concepts or objects (Correct answer)
Correct answer: Policy sets will replace existing concepts or objects
Policy sets in Intune are designed to group existing configuration objects (like apps, policies, and profiles) for easier assignment and management, especially for new device deployments. They are an additive feature to streamline workflows, not a replacement for existing concepts or objects. The other options describe valid characteristics of policy sets, such as grouping objects, cross-platform assignment capabilities, and limitations on what can be included.
Question 38: A company deploys apps via Intune and wants to remove an app that is no longer needed from all devices. Which assignment type achieves this?
- Required
- Available
- Uninstall (Correct answer)
- Not applicable
Correct answer: Uninstall
The 'Uninstall' assignment type in Intune removes the application from targeted devices or users automatically.
Question 39: The forest root domain contains objects that donβt exist in other domains in the forest.
- False
- True (Correct answer)
Correct answer: True
The forest root domain in Active Directory holds several unique objects and roles that are not replicated to other domains within the same forest. These include the Schema Master and Domain Naming Master FSMO roles, as well as enterprise-wide configurations and trust relationships that apply to the entire forest. Therefore, it contains objects specific to its role as the root.
Question 40: An administrator wants to assign specific Windows Autopilot deployment profiles to devices based on their department. Which mechanism in Intune achieves this?
- Endpoint analytics assignment
- SCEP certificate profiles
- Compliance policies with group filters
- Device categories and dynamic groups (Correct answer)
Correct answer: Device categories and dynamic groups
Device categories in Intune allow administrators to classify devices, which can then be used with dynamic Azure AD groups to automatically assign the correct Autopilot profile based on the device category.
Question 41: In Microsoft Intune, which profile type is used to configure Wi-Fi settings and push them to managed Windows devices?
- Device configuration profile (Correct answer)
- Endpoint protection profile
- Compliance policy
- Update ring
Correct answer: Device configuration profile
Device configuration profiles in Intune are used to push settings such as Wi-Fi networks, VPN connections, email, and certificates to managed devices.
Question 42: Which Intune feature allows IT to detect non-compliant device configurations and automatically remediate them using custom scripts?
- PowerShell scripts
- Endpoint security baselines
- Proactive remediations (Remediations) (Correct answer)
- Device compliance policy
Correct answer: Proactive remediations (Remediations)
Proactive remediations (now called Remediations) in Intune run detection and remediation script pairs to identify and fix configuration issues on managed Windows endpoints.
Question 43: Which Intune action performs a full factory reset of a company-owned Windows device to prepare it for redeployment?
- Wipe (Correct answer)
- Fresh Start
- Autopilot Reset
- Retire
Correct answer: Wipe
The Wipe action in Intune performs a full factory reset of the device, removing all data, apps, and settings, preparing it for redeployment or decommission.
Question 44: What is the primary requirement for a device to be eligible for Windows Autopilot?
- Device must have Windows 11 installed
- Device must have TPM 2.0
- Device must be domain-joined
- Device hardware hash must be registered in Intune/Autopilot (Correct answer)
Correct answer: Device hardware hash must be registered in Intune/Autopilot
A device's hardware hash (including device ID information) must be uploaded and registered in Windows Autopilot before it can be provisioned using Autopilot.
Question 45: A company is migrating users from Windows 10 to Windows 11 using in-place upgrades. Which Intune feature can trigger and manage these upgrades?
- Device compliance policy
- Endpoint security Antivirus policy
- Windows Update for Business Feature Update policy (Correct answer)
- Device configuration Delivery Optimization profile
Correct answer: Windows Update for Business Feature Update policy
Feature Update policies in Windows Update for Business allow administrators to define which Windows feature version devices should upgrade to and when, triggering in-place upgrades.
Question 46: What must be configured in Intune before Apple ADE (Automated Device Enrollment) can be used to enroll iPhones?
- An MDM server token from Apple Business Manager (Correct answer)
- An iOS device compliance policy
- An iOS configuration profile
- An Apple Push Notification certificate
Correct answer: An MDM server token from Apple Business Manager
An MDM server token (downloaded from Apple Business Manager and uploaded to Intune) is required to establish the trust between Intune and Apple's ADE service.
Question 47: Which join type requires an on-premises Active Directory domain and Azure AD tenant to both have a trust relationship via Azure AD Connect?
- Azure AD Registered
- Hybrid Azure AD Join (Correct answer)
- Azure AD Join
- Workgroup Join
Correct answer: Hybrid Azure AD Join
Hybrid Azure AD Join requires devices to be joined to on-premises AD and then synchronized to Azure AD via Azure AD Connect.
Question 48: What is the purpose of an Autopilot Deployment Profile?
- Define software packages to install during OOBE
- Set compliance policies for enrolled devices
- Configure Wi-Fi profiles for new devices
- Control the out-of-box experience settings for enrolled devices (Correct answer)
Correct answer: Control the out-of-box experience settings for enrolled devices
An Autopilot Deployment Profile controls OOBE settings such as whether to skip certain setup pages, hide privacy settings, and configure the deployment mode.
Question 49: Which Autopilot setting determines how the device joins Azure AD during deployment?
- Enrollment status page setting
- Join type (Correct answer)
- Deployment mode
- User account type
Correct answer: Join type
The Join type setting in an Autopilot deployment profile specifies whether the device performs a standard Azure AD join or a Hybrid Azure AD join that also joins the on-premises Active Directory domain.
Question 50: Which file contains the configuration settings for an unattended Windows installation, allowing administrators to automate responses to setup prompts?
- setup.ini
- autounattend.xml (Correct answer)
- winpeshl.ini
- bootstrap.cmd
Correct answer: autounattend.xml
The autounattend.xml file contains pre-defined answers to Windows setup prompts, enabling fully automated unattended installations when placed at the root of installation media.
MD-102 Exam
The MD-102 Microsoft Endpoint Administrator exam validates skills in deploying Windows client, managing identity and compliance, managing and protecting devices, and managing applications using Microsoft Intune and related technologies.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong β answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds