MD-102 Enrolling Devices with Microsoft Intune 2 — Questions and Answers
Question 1: Which enrollment method allows employees to enroll their personal Android devices while keeping personal and work data separate?
- Android Enterprise fully managed
- Android Enterprise personally-owned work profile (Correct answer)
- Android device administrator
- Android Enterprise dedicated device
Correct answer: Android Enterprise personally-owned work profile
Android Enterprise personally-owned work profile enrollment creates a separate encrypted work container on personal devices, keeping corporate and personal data isolated.
Question 2: What tool can be used to extract and upload Windows hardware hashes to Autopilot in bulk?
- Microsoft Deployment Toolkit
- Get-WindowsAutoPilotInfo PowerShell script (Correct answer)
- Windows Configuration Designer
- Microsoft Endpoint Configuration Manager
Correct answer: Get-WindowsAutoPilotInfo PowerShell script
The Get-WindowsAutoPilotInfo PowerShell script captures hardware hash information from devices and can upload it directly to Windows Autopilot.
Question 3: An administrator wants to prevent users from enrolling more than 3 devices into Intune. Where is this configured?
- Device compliance policy
- Device configuration profile
- Enrollment device limit restriction (Correct answer)
- Conditional Access policy
Correct answer: Enrollment device limit restriction
The device limit enrollment restriction in Intune controls the maximum number of devices a single user can enroll.
Question 4: Which Intune enrollment type is used for company-owned iOS devices that need to be enrolled without user interaction using Apple's DEP/ADE?
- Apple Configurator enrollment
- Automated Device Enrollment (ADE) (Correct answer)
- User enrollment
- BYOD enrollment
Correct answer: Automated Device Enrollment (ADE)
Automated Device Enrollment (formerly DEP) allows organizations to automatically enroll corporate-owned iOS devices into Intune without user interaction through Apple Business Manager.
Question 5: A device enrolled via Windows Autopilot self-deploying mode fails during enrollment. What is the most common cause?
- TPM 2.0 is not present or not attesting properly (Correct answer)
- The device does not have Wi-Fi
- The user's Azure AD password is expired
- The Autopilot profile is not assigned
Correct answer: TPM 2.0 is not present or not attesting properly
Self-deploying mode requires TPM 2.0 attestation for device authentication; if TPM is absent or not functioning correctly, enrollment will fail.
Question 6: What is the Enrollment Status Page (ESP) used for in Windows Autopilot?
- Showing compliance status after enrollment
- Blocking device use until required apps and policies are applied (Correct answer)
- Displaying device health information
- Notifying admins of enrollment failures
Correct answer: Blocking device use until required apps and policies are applied
The Enrollment Status Page blocks the user from accessing the desktop until all required applications and policies assigned in Intune have been successfully applied.
Which enrollment method allows employees to enroll their personal Android devices while keeping personal and work data separate?