MD-102 Exam — Questions and Answers
Question 1: A user has left the organization. Which action should an administrator take in Azure AD to immediately prevent the user from signing in?
- Delete the user account
- Revoke all refresh tokens
- Remove all group memberships
- Disable the user account (Correct answer)
Correct answer: Disable the user account
Disabling the user account in Azure AD immediately prevents sign-in while preserving the account, licenses, and data for potential recovery.
Question 2: You have a Microsoft 365 subscription that includes Microsoft Intune. <br> You plan to use Windows Autopilot to deploy Windows 11 devices. <br> You need to meet the following requirements during Autopilot provisioning: <br> * Display the app and profile configuration progress. <br> * Block users from using the devices until all apps and profiles are installed <br> What should you configure?
- an enrollment status page (Correct answer)
- an app protection policy
- an enrollment device platform restriction
- an app configuration policy
Correct answer: an enrollment status page
The Enrollment Status Page (ESP) in Windows Autopilot is designed to display the progress of device setup, including app and profile configuration. It can also be configured to block users from using the device until all required applications and profiles are successfully installed. This ensures that devices are fully provisioned and compliant before users gain access, meeting both requirements.
Question 3: Which Windows Autopilot deployment mode allows a technician to pre-configure a device before handing it to the end user?
- Pre-provisioning (white glove) mode (Correct answer)
- User-driven mode
- Reset mode
- Self-deploying mode
Correct answer: Pre-provisioning (white glove) mode
Pre-provisioning (white glove) mode allows IT staff or partners to complete the Autopilot provisioning process on behalf of the user so the device is fully configured before reaching the end user.
Question 4: Which file contains the configuration settings for an unattended Windows installation, allowing administrators to automate responses to setup prompts?
- autounattend.xml (Correct answer)
- setup.ini
- bootstrap.cmd
- winpeshl.ini
Correct answer: autounattend.xml
The autounattend.xml file contains pre-defined answers to Windows setup prompts, enabling fully automated unattended installations when placed at the root of installation media.
Question 5: An organisation wants to deploy Windows to new devices without physical media, ensuring Azure AD join and Intune enrollment automatically. Which solution is best?
- Windows Deployment Services (WDS)
- SCCM OSD Task Sequence
- MDT with PXE boot
- Windows Autopilot (Correct answer)
Correct answer: Windows Autopilot
Windows Autopilot enables zero-touch deployment where devices are automatically configured, Azure AD-joined, and Intune-enrolled out of the box without physical media or on-premises infrastructure.
Question 6: Which of the following statements NOT true about policy sets?
- Used for group objects that need to be assigned together
- Policy sets will replace existing concepts or objects (Correct answer)
- It can be assigned as cross-platform
- The default restrictions and ESP cannot be added to a policy set
Correct answer: Policy sets will replace existing concepts or objects
Policy sets in Intune are designed to group existing configuration objects (like apps, policies, and profiles) for easier assignment and management, especially for new device deployments. They are an additive feature to streamline workflows, not a replacement for existing concepts or objects. The other options describe valid characteristics of policy sets, such as grouping objects, cross-platform assignment capabilities, and limitations on what can be included.
Question 7: What are detection rules used for when deploying Win32 apps in Intune?
- To verify the app was successfully installed on the device (Correct answer)
- To check if the device is compliant before installing the app
- To specify the installation command for the app
- To define which users are authorized to install the app
Correct answer: To verify the app was successfully installed on the device
Detection rules in Intune Win32 app deployments define how Intune determines whether the application is already installed on a device, preventing redundant reinstallation.
Question 8: What is the purpose of an Autopilot Deployment Profile?
- Define software packages to install during OOBE
- Configure Wi-Fi profiles for new devices
- Control the out-of-box experience settings for enrolled devices (Correct answer)
- Set compliance policies for enrolled devices
Correct answer: Control the out-of-box experience settings for enrolled devices
An Autopilot Deployment Profile controls OOBE settings such as whether to skip certain setup pages, hide privacy settings, and configure the deployment mode.
Question 9: A device has a pending feature update but the user has declined the restart multiple times. If a deadline is set to 3 days with a 2-day grace period, when will the device force restart?
- After 3 days from update availability
- After the user accepts the restart prompt
- After 5 days from update availability (Correct answer)
- After 2 days from update availability
Correct answer: After 5 days from update availability
The device will force restart after the deadline period (3 days) plus the grace period (2 days), totaling 5 days from when the update became available.
Question 10: What is the minimum requirement for a device to be eligible for Windows Autopilot deployment?
- The device hardware hash must be registered in Intune or Autopilot (Correct answer)
- The device must have Windows 10 Pro or higher installed
- The device must have a TPM 2.0 chip
- The device must be domain-joined
Correct answer: The device hardware hash must be registered in Intune or Autopilot
For Autopilot to recognise and configure a device automatically, its hardware hash must be registered in Microsoft Intune or the Autopilot deployment service.
Question 11: An administrator wants to prevent users from copying corporate data from Microsoft 365 apps to personal apps on Windows devices. Which Intune feature addresses this?
- Device compliance policy
- Endpoint security Firewall policy
- App protection policies (MAM) (Correct answer)
- Device configuration Device restrictions
Correct answer: App protection policies (MAM)
App protection policies (Mobile Application Management) in Intune can restrict data transfer between managed apps and unmanaged personal apps, preventing corporate data leakage.
Question 12: A company is migrating users from Windows 10 to Windows 11 using in-place upgrades. Which Intune feature can trigger and manage these upgrades?
- Windows Update for Business Feature Update policy (Correct answer)
- Device configuration Delivery Optimization profile
- Device compliance policy
- Endpoint security Antivirus policy
Correct answer: Windows Update for Business Feature Update policy
Feature Update policies in Windows Update for Business allow administrators to define which Windows feature version devices should upgrade to and when, triggering in-place upgrades.
Question 13: Which Windows feature allows you to connect a device to a corporate network securely over the internet?
- VPN (Correct answer)
- Wi-Fi Direct
- Bluetooth PAN
- DirectAccess
Correct answer: VPN
VPN (Virtual Private Network) allows devices to securely connect to a corporate network over the internet by encrypting traffic through a tunnel.
Question 14: Which Windows Update for Business policy type controls when quality updates (monthly cumulative updates) are installed on managed devices?
- Quality update policy via Update ring (Correct answer)
- Driver update policy
- Feature update policy
- Expedite update policy
Correct answer: Quality update policy via Update ring
Update rings in Windows Update for Business define deferral periods and deadlines for quality updates, controlling when monthly cumulative updates are installed on groups of devices.
Question 15: An administrator needs to ensure that Windows 11 devices automatically connect to the corporate VPN whenever a user signs in. Which solution should be used?
- Split-tunnel VPN
- Always On VPN (Correct answer)
- DirectAccess
- Per-app VPN only
Correct answer: Always On VPN
Always On VPN automatically establishes a VPN connection when a user signs in, ensuring seamless and persistent secure connectivity without manual intervention.
Question 16: An organisation wants Windows devices to automatically restart after updates but only during a specific maintenance window. Which Intune setting controls this?
- Conditional access enforcement
- Active hours setting in Update ring (Correct answer)
- Autopilot deployment timing
- Compliance policy restart grace period
Correct answer: Active hours setting in Update ring
Active hours in Windows Update for Business Update rings define the period when users are likely active. Restarts are scheduled outside of active hours to minimise disruption.
Question 17: An administrator needs to remotely remove all corporate data from a user Windows device while leaving personal data intact. Which Intune action achieves this?
- Delete
- Retire (Correct answer)
- Fresh Start
- Wipe (full factory reset)
Correct answer: Retire
The Retire action in Intune removes corporate-managed apps, policies, and data from a device while leaving personal data and settings intact, making it suitable for BYOD offboarding.
Question 18: An endpoint administrator configures an update ring with a 10-day feature update deferral. What is the maximum deferral period allowed for feature updates?
- 90 days
- 180 days
- 365 days (Correct answer)
- 730 days
Correct answer: 365 days
Feature updates can be deferred for up to 365 days (one year) using Windows Update for Business policies configured in Microsoft Intune.
Question 19: Which authentication strength setting in Azure AD Conditional Access enforces phishing-resistant MFA methods only?
- MFA strength
- Windows Hello strength
- Phishing-resistant MFA strength (Correct answer)
- Passwordless MFA strength
Correct answer: Phishing-resistant MFA strength
The Phishing-resistant MFA strength in Conditional Access restricts authentication to methods immune to phishing, such as FIDO2 keys and Windows Hello for Business.
Question 20: Which app protection policy setting prevents users from taking screenshots of corporate data in managed apps on Android?
- Block screen capture and Android Assistant (Correct answer)
- Require PIN for access
- Restrict cut, copy, and paste
- Save copies of org data
Correct answer: Block screen capture and Android Assistant
The 'Block screen capture and Android Assistant' setting in Intune app protection policies prevents screenshots of corporate app content on Android devices.
Question 21: What is the Enrollment Status Page (ESP) used for in Windows Autopilot?
- Showing compliance status after enrollment
- Blocking device use until required apps and policies are applied (Correct answer)
- Notifying admins of enrollment failures
- Displaying device health information
Correct answer: Blocking device use until required apps and policies are applied
The Enrollment Status Page blocks the user from accessing the desktop until all required applications and policies assigned in Intune have been successfully applied.
Question 22: Which co-management workload must be switched to Intune to manage Windows Update policies using Windows Update for Business rings?
- Windows Update policies (Correct answer)
- Resource access policies
- Endpoint Protection
- Device compliance
Correct answer: Windows Update policies
The Windows Update policies co-management workload must be switched to Intune to allow Intune-based Windows Update for Business rings to take effect.
Question 23: Which Autopilot setting determines how the device joins Azure AD during deployment?
- Join type (Correct answer)
- Deployment mode
- User account type
- Enrollment status page setting
Correct answer: Join type
The Join type setting in an Autopilot deployment profile specifies whether the device performs a standard Azure AD join or a Hybrid Azure AD join that also joins the on-premises Active Directory domain.
Question 24: An administrator needs to ensure that only compliant devices can access Microsoft 365 resources. Which Azure AD feature should be configured?
- Identity Protection
- Access Reviews
- Conditional Access (Correct answer)
- Privileged Identity Management
Correct answer: Conditional Access
Conditional Access policies in Azure AD can enforce that only devices marked compliant by Intune are permitted to access Microsoft 365 resources.
Question 25: What is the purpose of app requirement rules in Win32 app deployment in Intune?
- Set the minimum OS version for the device
- Define prerequisites that must be met before the app installation begins (Correct answer)
- Configure app assignment groups
- Detect if the app is already installed
Correct answer: Define prerequisites that must be met before the app installation begins
Requirement rules in Intune Win32 app deployment define prerequisite conditions (such as OS version, disk space, or registry keys) that must be satisfied before Intune attempts to install the app.
Question 26: Which tool is used to capture a Windows image (.wim file) for deployment using Microsoft Deployment Toolkit (MDT)?
- Sysprep
- DISM (Deployment Image Servicing and Management) (Correct answer)
- Windows SIM (System Image Manager)
- WinPE Boot Media Creator
Correct answer: DISM (Deployment Image Servicing and Management)
DISM is the command-line tool used to capture, service, and apply Windows image files (.wim), making it the primary tool for creating deployment images.
Question 27: A company wants to enforce multi-factor authentication for all admin sign-ins to Azure AD. What is the simplest way to enforce this for all global administrators?
- Security defaults (Correct answer)
- Conditional Access policy
- Per-user MFA
- Identity Protection policy
Correct answer: Security defaults
Security defaults in Azure AD automatically require MFA for all administrators and provide baseline identity protection with minimal configuration.
Question 28: Your network contains an Active Directory domain named contoso.com. The domain contains 25 computers that run Windows 11. You have a Microsoft 365 subscription You have an Azure AD tenant that syncs with contoso.com. You configure hybrid Azure AD join and discover that some of the computers have a registered state of Pending. You need to ensure that the computers complete the join successfully. <br> What should you ensure?
- that the computers contain the latest quality updates
- that Windows is activated on all the computers
- that each computer has a line of sight to a domain controller (Correct answer)
- that the users of the computers are assigned Microsoft 365 licenses
Correct answer: that each computer has a line of sight to a domain controller
For hybrid Azure AD join to complete successfully, the computers need to be able to communicate directly with an on-premises Active Directory domain controller. This 'line of sight' is crucial for the device registration process, as the domain controller is responsible for syncing the device object to Azure AD. Without this connectivity, the device registration can remain in a 'Pending' state.
Question 29: Which Intune enrollment type is used for company-owned iOS devices that need to be enrolled without user interaction using Apple's DEP/ADE?
- User enrollment
- BYOD enrollment
- Apple Configurator enrollment
- Automated Device Enrollment (ADE) (Correct answer)
Correct answer: Automated Device Enrollment (ADE)
Automated Device Enrollment (formerly DEP) allows organizations to automatically enroll corporate-owned iOS devices into Intune without user interaction through Apple Business Manager.
Question 30: An administrator notices that some devices show 'Update error' in the Intune update rings report. Which built-in Intune report helps identify specific error codes for failed update installations?
- Windows Update rings report - Per setting status
- Windows update failure details report (Correct answer)
- Endpoint analytics startup performance
- Device compliance report
Correct answer: Windows update failure details report
The Windows update failure details report in Intune provides specific error codes, affected device counts, and remediation guidance for failed Windows update installations.
Question 31: An administrator wants to test feature updates on a pilot group before deploying to all users. Which Intune feature enables this staged deployment approach?
- Update rings
- Windows Autopatch
- Compliance policies
- Feature update deployments (Correct answer)
Correct answer: Feature update deployments
Feature update deployments in Intune allow administrators to target specific Windows feature update versions to designated device groups for controlled rollout.
Question 32: Your network contains an Active Directory domain. The domain contains 10 computers that run Windows 10. Users in the finance department use the computers. You have a computer named Computer1 that runs Windows 10. From Computer1, you plan to run a script that executes Windows PowerShell commands on the finance department computers. You need to ensure that you can run the PowerShell commands on the finance department computers from Computer. What should you do on the finance department computers?
- From Windows PowerShell, run the Enable-PSRemoting cmdlet. (Correct answer)
- From the local Group Policy, enable the Allow Remote Shell Access setting.
- From the local Group Policy, enable the Turn on Script Execution setting.
- From Windows PowerShell, run the Enable-MMAgent cmdlet.
Correct answer: From Windows PowerShell, run the Enable-PSRemoting cmdlet.
To enable running PowerShell commands remotely on the finance department computers from Computer1, you must execute the `Enable-PSRemoting` cmdlet on each target finance department computer. This cmdlet configures the necessary firewall rules and starts the WinRM service, allowing PowerShell remoting connections. Without enabling PSRemoting, remote execution of PowerShell commands will not be possible.
Question 33: An update ring in Intune is set to 'Pause quality updates.' How long can quality updates be paused before the pause automatically expires?
- 7 days
- 14 days
- 35 days (Correct answer)
- 21 days
Correct answer: 35 days
Quality update pauses in Intune update rings automatically expire after 35 days, after which the device will resume receiving quality updates.
Question 34: A company deploys apps via Intune and wants to remove an app that is no longer needed from all devices. Which assignment type achieves this?
- Required
- Available
- Not applicable
- Uninstall (Correct answer)
Correct answer: Uninstall
The 'Uninstall' assignment type in Intune removes the application from targeted devices or users automatically.
Question 35: What is the purpose of running Sysprep /generalize before capturing a Windows image?
- It installs the latest Windows updates on the reference device
- It compresses the Windows image to save disk space
- It enables BitLocker on the reference device
- It removes machine-specific information so the image can be deployed to multiple devices (Correct answer)
Correct answer: It removes machine-specific information so the image can be deployed to multiple devices
Sysprep /generalize removes machine-specific data such as the SID and hardware identifiers, allowing the same image to be deployed to many different devices, each receiving a unique identity.
Question 36: An administrator wants to require devices to be Azure AD joined before granting access to a SharePoint site. Which policy type should be used?
- Azure AD Conditional Access policy (Correct answer)
- Intune compliance policy
- Azure AD Identity Protection policy
- Microsoft Defender policy
Correct answer: Azure AD Conditional Access policy
An Azure AD Conditional Access policy can require a device to be Azure AD joined as a condition before granting access to specific cloud apps like SharePoint.
Question 37: Which Intune action performs a full factory reset of a company-owned Windows device to prepare it for redeployment?
- Retire
- Fresh Start
- Autopilot Reset
- Wipe (Correct answer)
Correct answer: Wipe
The Wipe action in Intune performs a full factory reset of the device, removing all data, apps, and settings, preparing it for redeployment or decommission.
Question 38: Which Windows Defender feature protects specific folders (like Documents and Desktop) from unauthorized changes by ransomware?
- Application Guard
- Network protection
- Controlled folder access (Correct answer)
- Attack surface reduction rules
Correct answer: Controlled folder access
Controlled folder access monitors and protects designated folders from unauthorized changes by untrusted apps, providing protection against ransomware.
Question 39: Which Self-Service Password Reset (SSPR) setting allows users to reset their password using an authenticator app notification?
- Mobile app notification (Correct answer)
- Security questions
- Email authentication
- Office phone
Correct answer: Mobile app notification
The mobile app notification method in SSPR allows users to approve a password reset through a push notification sent to their Microsoft Authenticator app.
Question 40: You have a Microsoft 365 E5 subscription that uses Microsoft Intune. Vou configure Intune to send log data to Log Analytics. You need to review events involving devices that fail to enroll in Intune. What should you monitor?
- device compliance organizational logs
- audit logs
- the Intune Device log (Correct answer)
- operational logs
Correct answer: the Intune Device log
To review events related to devices failing to enroll in Intune, you should monitor the Intune Device log. This log specifically captures information about device enrollment, compliance, and other device-related activities. When integrated with Log Analytics, these logs provide detailed insights into enrollment failures, helping administrators troubleshoot and resolve issues efficiently.
Question 41: You have a Microsoft 365 subscription that includes Microsoft Intune. The subscription contains corporate-owned, fully managed Android Enterprise devices. You plan to deploy a configuration profile that will have a device restrictions profile type named Profile1. Profile1 will assign maintenance windows for system updates. <br> What should you configure from the Configuration settings for Profile1?
- Connectivity
- General
- Power Settings Explanation
- Device experience (Correct answer)
Correct answer: Device experience
For Android Enterprise corporate-owned, fully managed devices, settings related to system updates, including defining maintenance windows, are found under the "Device experience" category within a device restrictions configuration profile. This section allows administrators to control various aspects of the device's user experience and operational behavior, such as update policies, kiosk modes, and display settings.
Question 42: Which Intune report shows how many devices have a specific application installed?
- Device configuration report
- App install status report (Correct answer)
- Device compliance report
- Endpoint analytics app reliability report
Correct answer: App install status report
The app install status report in Intune shows the installation status of a specific app across all targeted devices, including successful installations, failures, and pending installations.
Question 43: Which Azure AD feature can automatically detect risky sign-in events and prompt for MFA or block access based on a risk score?
- Identity Protection (Correct answer)
- Conditional Access
- Access Reviews
- Privileged Identity Management
Correct answer: Identity Protection
Azure AD Identity Protection evaluates sign-in risk using machine learning and can automatically enforce MFA or block access based on the detected risk level.
Question 44: Which prerequisite must be met on the Configuration Manager side to enable co-management with Intune?
- All clients must be upgraded to the latest CCM agent
- Configuration Manager must be version 1902 or later (Correct answer)
- Configuration Manager must be hosted in Azure
- Devices must be Azure AD joined only
Correct answer: Configuration Manager must be version 1902 or later
Co-management requires Configuration Manager version 1902 or later (or current branch) to support the integration with Microsoft Intune.
Question 45: Which report in Microsoft Intune provides visibility into the update status of enrolled Windows devices, including devices that are pending, in progress, or successfully updated?
- Feature update failures report
- Windows Update for Business reports
- Device compliance report
- Windows Update rings report (Correct answer)
Correct answer: Windows Update rings report
The Windows Update rings report in Intune shows per-device update status for enrolled devices assigned to update ring policies, including pending, in progress, and completed states.
Question 46: Which tool provides detailed Windows Update for Business reporting data integrated with Azure Monitor and Log Analytics?
- Microsoft Defender for Endpoint
- Microsoft Endpoint Analytics
- Windows Update for Business reports (Correct answer)
- Intune Data Warehouse
Correct answer: Windows Update for Business reports
Windows Update for Business reports is a cloud-based solution that provides detailed update deployment data in Azure Monitor and Log Analytics workbooks for deep analysis.
Question 47: Which Intune feature allows IT to detect non-compliant device configurations and automatically remediate them using custom scripts?
- PowerShell scripts
- Endpoint security baselines
- Proactive remediations (Remediations) (Correct answer)
- Device compliance policy
Correct answer: Proactive remediations (Remediations)
Proactive remediations (now called Remediations) in Intune run detection and remediation script pairs to identify and fix configuration issues on managed Windows endpoints.
Question 48: Which Intune endpoint security policy configures Windows Firewall rules on managed devices?
- Device compliance – Windows
- Endpoint security – Antivirus
- Device configuration – Endpoint protection
- Endpoint security – Firewall (Correct answer)
Correct answer: Endpoint security – Firewall
The Endpoint security Firewall policy in Intune is specifically designed to configure Windows Firewall settings and rules on managed Windows devices.
Question 49: What does the Enrollment Status Page (ESP) do during Windows Autopilot deployment?
- It records the device in the Autopilot hardware hash database
- It blocks the user from accessing the desktop until required apps and policies are applied (Correct answer)
- It sends an email notification when enrollment is complete
- It captures diagnostic logs and uploads them to Intune
Correct answer: It blocks the user from accessing the desktop until required apps and policies are applied
The Enrollment Status Page prevents the user from accessing the desktop or apps until all required configurations, applications, and policies have been successfully applied to the device.
Question 50: An iOS app protection policy is configured with a PIN requirement. On which event will the user be prompted for the PIN?
- Only after a device restart
- Every time the user opens any app on the device
- When the app is opened after the defined inactivity timeout (Correct answer)
- Every time the device is unlocked
Correct answer: When the app is opened after the defined inactivity timeout
App protection policy PIN prompts appear when a managed app is accessed after the configured inactivity timeout period has elapsed.
MD-102 Exam
The MD-102 Microsoft Endpoint Administrator exam validates skills in deploying Windows client, managing identity and compliance, managing and protecting devices, and managing applications using Microsoft Intune and related technologies.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds