MS-102 Microsoft 365 Administrator Expert Managing Intune and Device Compliance 2 — Questions and Answers
Question 1: In which section of an Intune device compliance policy can an administrator specify minimum and maximum allowed operating system versions for enrolled devices?
- Device health
- System security
- Device properties (Correct answer)
- Endpoint protection
Correct answer: Device properties
The Device properties section of an Intune compliance policy contains settings for specifying minimum and maximum OS versions that enrolled devices must meet.
Question 2: An administrator needs to automatically push Wi-Fi credentials to all managed iOS devices so users do not need to enter them manually. Which Intune feature accomplishes this?
- App protection policies
- Configuration profiles (Correct answer)
- Compliance policies
- Device enrollment restrictions
Correct answer: Configuration profiles
Intune configuration profiles allow administrators to push device settings such as Wi-Fi networks, certificates, and VPN configurations directly to managed iOS/iPadOS devices.
Question 3: What is the purpose of the Enrollment Status Page (ESP) in a Windows Autopilot deployment?
- To display Intune license assignment status during setup
- To block device access until required apps and policies are fully applied (Correct answer)
- To show the hardware inventory collected during enrollment
- To authenticate the user with Multi-Factor Authentication before OOBE
Correct answer: To block device access until required apps and policies are fully applied
The Enrollment Status Page prevents users from accessing the desktop until specified apps and configurations have been successfully applied, ensuring the device is in a managed state before first use.
Question 4: What does the Intune 'Retire' remote action do to a managed device?
- Wipes the device to factory settings and removes it from Azure AD
- Removes corporate data and unenrolls the device while leaving personal data intact (Correct answer)
- Locks the device remotely until the user enters a PIN
- Removes only the Intune Management Extension from the device
Correct answer: Removes corporate data and unenrolls the device while leaving personal data intact
Retire removes company-managed apps, email profiles, certificates, and Intune enrollment from the device while leaving personal data and apps untouched, making it ideal for BYOD offboarding.
Question 5: An administrator wants to prevent corporate Windows 11 devices from allowing users to sign in with personal Microsoft accounts. Which Intune configuration profile type contains this setting?
- Endpoint protection
- Device restrictions (Correct answer)
- Identity protection
- Custom OMA-URI
Correct answer: Device restrictions
Device restriction profiles in Intune include settings to block Microsoft accounts and other consumer features on Windows 10/11 devices, keeping devices focused on corporate identities.
Question 6: Which Intune feature allows administrators to deploy traditional Win32 applications (.exe or .msi) to Windows 10/11 managed devices?
- Microsoft Store for Business app deployment
- Win32 app deployment via the Intune Management Extension (IME) (Correct answer)
- Windows Package Manager (winget) integration
- SCCM co-management with workload shift only
Correct answer: Win32 app deployment via the Intune Management Extension (IME)
The Intune Management Extension (IME) agent enables Win32 app packaging and deployment to Intune-managed Windows devices, supporting complex installation scenarios with detection rules.
Question 7: Which Intune report provides a comprehensive view of all enrolled devices and their current compliance state, including Not compliant, Compliant, In grace period, and Not evaluated?
- Device inventory report
- Device compliance report (Correct answer)
- Endpoint analytics report
- App install status report
Correct answer: Device compliance report
The Device compliance report in Intune shows all enrolled devices and their compliance state across all compliance policies assigned to them.
In which section of an Intune device compliance policy can an administrator specify minimum and maximum allowed operating system versions for enrolled devices?