MD-102 Monitoring and Reporting in Endpoint Management 2 — Questions and Answers
Question 1: An administrator wants to trigger an immediate policy sync on a Windows 10 device managed by Intune without waiting for the next scheduled check-in. What should the admin do?
- Restart the device remotely
- Use the Sync action from the device in Intune portal (Correct answer)
- Reinstall the Intune Management Extension
- Delete and re-enroll the device
Correct answer: Use the Sync action from the device in Intune portal
The Sync remote action in the Intune portal sends a notification to the device to check in immediately and pull down any pending policy or app updates.
Question 2: Which diagnostic tool is available in Intune to collect logs and diagnostic data from a managed Windows 10 device for troubleshooting?
- Intune device diagnostics
- Collect diagnostics remote action (Correct answer)
- Windows Event Viewer export
- Microsoft Support and Recovery Assistant
Correct answer: Collect diagnostics remote action
The Collect diagnostics remote action in Intune gathers diagnostic logs from the managed device and uploads them to the Intune portal for administrator review.
Question 3: Which Intune feature allows administrators to run queries on managed device inventory and configuration data using KQL?
- Endpoint analytics
- Intune Data Warehouse (Correct answer)
- Microsoft Defender hunting
- Advanced hunting in Microsoft Intune (via MDE integration)
Correct answer: Intune Data Warehouse
The Intune Data Warehouse provides historical device and compliance data that can be queried using Power BI or OData feeds, while advanced hunting uses KQL in Microsoft 365 Defender.
Question 4: A Windows 10 device shows as 'Not evaluated' in the Intune compliance report. What is the most likely reason?
- The device has no compliance policies assigned (Correct answer)
- The device is not connected to the internet
- The device is pending a restart
- The Intune enrollment is corrupted
Correct answer: The device has no compliance policies assigned
A 'Not evaluated' compliance status in Intune occurs when no compliance policy has been assigned to the device or user, so no evaluation has taken place.
Question 5: Which Microsoft service provides a centralized security dashboard that aggregates alerts from Defender for Endpoint, Intune compliance, and identity risk?
- Microsoft Intune admin center
- Microsoft 365 Defender portal (Correct answer)
- Azure Security Center
- Microsoft Compliance Manager
Correct answer: Microsoft 365 Defender portal
The Microsoft 365 Defender portal (security.microsoft.com) aggregates security signals from Defender for Endpoint, Defender for Identity, and other services into a unified security dashboard.
Question 6: An administrator needs to see which users have the most device compliance failures across the organization. Which Intune report provides this information?
- Non-compliant devices report
- Noncompliant policies report
- Device compliance – Per user compliance report (Correct answer)
- Audit logs
Correct answer: Device compliance – Per user compliance report
The per-user compliance report in Intune shows compliance status broken down by user, allowing administrators to identify users with the most compliance issues.
An administrator wants to trigger an immediate policy sync on a Windows 10 device managed by Intune without waiting for the next scheduled check-in.
What should the admin do?