MS-900 MS-900 - Microsoft 365 Fundamentals Modern Device and Endpoint Management 1 — Questions and Answers
Question 1: Which Microsoft 365 service is used to manage and secure mobile devices, PCs, and apps from the cloud?
- Azure Active Directory
- Microsoft Intune (Correct answer)
- Microsoft Defender for Endpoint
- Microsoft Purview
Correct answer: Microsoft Intune
Microsoft Intune is the cloud-based Mobile Device Management (MDM) and Mobile Application Management (MAM) service within Microsoft 365.
Question 2: What is the primary function of Microsoft Endpoint Manager?
- Managing email endpoints and spam filters
- Unified platform combining Intune and Configuration Manager for device management (Correct answer)
- Monitoring network endpoints for security threats
- Managing API endpoints for Microsoft 365 services
Correct answer: Unified platform combining Intune and Configuration Manager for device management
Microsoft Endpoint Manager is the unified console that brings together Microsoft Intune and Configuration Manager for comprehensive endpoint management.
Question 3: What is 'Mobile Application Management' (MAM) in Microsoft Intune primarily used for?
- Managing the mobile data plan of company phones
- Controlling and protecting corporate data within mobile apps without enrolling the device (Correct answer)
- Tracking the physical location of mobile devices
- Installing mobile apps via the app store
Correct answer: Controlling and protecting corporate data within mobile apps without enrolling the device
MAM in Intune lets organizations protect corporate data within apps on personal (BYOD) devices without requiring full device enrollment.
Question 4: Which Windows 10/11 feature enables devices to be automatically configured and enrolled into management when a user signs in with their Azure AD credentials?
- Windows Hello for Business
- Windows Autopilot (Correct answer)
- BitLocker
- Windows Defender
Correct answer: Windows Autopilot
Windows Autopilot automates device setup and enrollment into Microsoft Intune when users sign in with their organizational credentials, eliminating manual IT imaging.
Question 5: What does 'Conditional Access' in Microsoft 365 primarily enforce?
- Restricting internet bandwidth usage
- Requiring specific conditions (like compliant device or MFA) before granting access to resources (Correct answer)
- Filtering conditional logic in SharePoint lists
- Setting conditions for email auto-replies
Correct answer: Requiring specific conditions (like compliant device or MFA) before granting access to resources
Conditional Access in Azure AD enforces policies that require users to meet specific conditions—such as MFA or device compliance—before accessing Microsoft 365 resources.
Question 6: Which Microsoft 365 feature allows organizations to ensure only compliant and healthy devices can access corporate resources?
- Microsoft Defender Antivirus
- Device Compliance Policies in Intune (Correct answer)
- Microsoft Purview Information Protection
- Azure AD Password Protection
Correct answer: Device Compliance Policies in Intune
Device compliance policies in Microsoft Intune define the rules and settings devices must meet, and Conditional Access blocks non-compliant devices from accessing resources.
Which Microsoft 365 service is used to manage and secure mobile devices, PCs, and apps from the cloud?