MD-102 Enrolling Devices with Microsoft Intune 3 — Questions and Answers
Question 1: Which co-management workload must be switched to Intune to manage Windows Update policies using Windows Update for Business rings?
- Device compliance
- Windows Update policies (Correct answer)
- Resource access policies
- Endpoint Protection
Correct answer: Windows Update policies
The Windows Update policies co-management workload must be switched to Intune to allow Intune-based Windows Update for Business rings to take effect.
Question 2: A company is using Configuration Manager and wants to start managing devices with Intune as well. What feature enables both tools to manage the same devices simultaneously?
- Tenant attach
- Co-management (Correct answer)
- Autopilot hybrid join
- Intune gateway
Correct answer: Co-management
Co-management allows devices to be simultaneously managed by both Configuration Manager and Microsoft Intune, with workloads split between the two tools.
Question 3: Which prerequisite must be met on the Configuration Manager side to enable co-management with Intune?
- Configuration Manager must be version 1902 or later (Correct answer)
- All clients must be upgraded to the latest CCM agent
- Devices must be Azure AD joined only
- Configuration Manager must be hosted in Azure
Correct answer: Configuration Manager must be version 1902 or later
Co-management requires Configuration Manager version 1902 or later (or current branch) to support the integration with Microsoft Intune.
Question 4: An admin wants to enroll Android devices in a mode where the company owns and fully manages the entire device. Which enrollment type should be used?
- Android Enterprise work profile
- Android Enterprise fully managed (Correct answer)
- Android Enterprise dedicated
- Android device administrator
Correct answer: Android Enterprise fully managed
Android Enterprise fully managed enrollment gives the organization complete control over the entire device, typically used for corporate-owned devices with a single primary user.
Question 5: What must be configured in Intune before Apple ADE (Automated Device Enrollment) can be used to enroll iPhones?
- An Apple Push Notification certificate
- An MDM server token from Apple Business Manager (Correct answer)
- An iOS device compliance policy
- An iOS configuration profile
Correct answer: An MDM server token from Apple Business Manager
An MDM server token (downloaded from Apple Business Manager and uploaded to Intune) is required to establish the trust between Intune and Apple's ADE service.
Question 6: A Windows 11 device is being enrolled via Autopilot User-Driven mode. The user's account is not assigned an Autopilot profile. What will happen during OOBE?
- The device will proceed with a standard consumer OOBE (Correct answer)
- Enrollment will fail with an error
- The device will be enrolled using a default profile
- The device will wait indefinitely for a profile
Correct answer: The device will proceed with a standard consumer OOBE
If no Autopilot deployment profile is assigned to the device or user, Windows will present the standard consumer out-of-box experience instead of a customized corporate setup.
Which co-management workload must be switched to Intune to manage Windows Update policies using Windows Update for Business rings?