CertSafari

    Free Microsoft Certified: Endpoint Administrator Associate (MD-102) Sample Questions

    35 free sample questions from our bank of 349+, covering every exam domain, with answers and detailed explanations. Updated September 2026.

    Domain 1: Prepare infrastructure for devices

    Subdomain 1.1: Add devices to Microsoft Entra ID

    1.What is the maximum number of characters allowed in the body of a single dynamic membership rule in Microsoft Entra ID?

    1. A.1,024
    2. B.2,048
    3. C.3,072
    4. D.4,096
    Show answer & explanation

    Correct answer: C3,072

    • A. This is smaller than the actual documented character limit for a dynamic membership rule body.
    • B. This is smaller than the actual documented character limit for a dynamic membership rule body.
    • C. This is the documented maximum length for the body of a dynamic membership rule in Microsoft Entra ID.
    • D. This exceeds the actual documented character limit for a dynamic membership rule body.

    Subdomain 1.1: Add devices to Microsoft Entra ID

    2.An admin has deleted a Microsoft Entra hybrid joined device from Intune and deregistered it from Windows Autopilot. What additional step is required to fully remove the device and prevent it from resyncing to Microsoft Entra ID?

    1. A.Delete the corresponding computer object from the on-premises Active Directory Domain Services environment.
    2. B.Manually delete the device object directly from Microsoft Entra ID using the admin center.
    3. C.Disable the device's Windows Hello for Business certificate in Intune.
    4. D.Remove the device from the Microsoft 365 admin center Autopilot device list.
    Show answer & explanation

    Correct answer: ADelete the corresponding computer object from the on-premises Active Directory Domain Services environment.

    • A. For hybrid joined devices, the on-premises AD computer object must be deleted, otherwise the next AD sync cycle recreates the device object in Microsoft Entra ID.
    • B. Manually deleting the device object from Microsoft Entra ID is explicitly discouraged, since the deregistration and cleanup process is meant to handle related records correctly on its own.
    • C. Certificate management for Windows Hello for Business has no effect on whether the device record resyncs from on-premises AD.
    • D. This admin center is an alternative place to deregister from Autopilot, but it does not address the on-premises AD object that causes hybrid joined devices to resync.

    Subdomain 1.1: Add devices to Microsoft Entra ID

    3.Which statements about dynamic membership groups in Microsoft Entra ID are accurate? (Select all that apply.)(Select 3)

    1. A.A single Microsoft Entra tenant can have a maximum of 15,000 dynamic membership groups total.
    2. B.No license is required for devices that are members of a device-based dynamic membership group.
    3. C.A single membership rule can contain both user and device objects in the same group.
    4. D.The Microsoft Entra ID P1 license requirement is based on unique users across all dynamic groups.
    5. E.Dynamic membership groups don't allow admins to manually add or remove individual members.
    6. F.Security groups and Microsoft 365 groups can both contain either devices or users.
    Show answer & explanation

    Correct answers: A, B, DA single Microsoft Entra tenant can have a maximum of 15,000 dynamic membership groups total.; No license is required for devices that are members of a device-based dynamic membership group.; The Microsoft Entra ID P1 license requirement is based on unique users across all dynamic groups.

    • A. This matches the documented tenant-wide limit on the number of dynamic membership groups that can exist.
    • B. Devices that qualify for a device-based dynamic group do not require any per-device license, unlike users in dynamic groups.
    • C. A dynamic membership group and its rule must be exclusively user-based or device-based; the two object types cannot be combined in one rule.
    • D. The P1 licensing requirement counts each unique user who belongs to at least one dynamic membership group across the tenant, not per group.
    • E. Because membership is calculated automatically from the rule, administrators cannot manually add or remove individual members from a dynamic group.
    • F. Only security groups can contain devices; Microsoft 365 groups are limited to user members, so this statement misstates the actual restriction.

    Subdomain 1.2: Enroll devices to Microsoft Intune

    4.Which statement accurately describes using Group Policy to trigger automatic Intune enrollment for Windows devices?

    1. A.It triggers automatic enrollment through a scheduled task after a Microsoft Entra ID-synced user signs in on a hybrid joined device.
    2. B.It requires Windows Autopilot self-deploying mode to be configured alongside the same Group Policy object.
    3. C.It enrolls devices only after a factory reset, since Group Policy enrollment always needs a clean OS image.
    4. D.It applies only to Microsoft Entra joined devices that were never part of an on-premises Active Directory domain.
    Show answer & explanation

    Correct answer: AIt triggers automatic enrollment through a scheduled task after a Microsoft Entra ID-synced user signs in on a hybrid joined device.

    • A. Group Policy-triggered enrollment is recommended for Microsoft Entra hybrid joined devices and starts a background scheduled task after a Microsoft Entra ID-synced user signs in, with no user interaction required.
    • B. Group Policy enrollment is an alternative to Autopilot self-deploying mode, not a requirement layered on top of it; the two are separate enrollment mechanisms.
    • C. Group Policy enrollment does not require a factory reset; it works against already domain-joined devices that are Microsoft Entra hybrid joined.
    • D. Group Policy-based automatic enrollment specifically targets Microsoft Entra hybrid joined devices, which by definition are also joined to an on-premises Active Directory domain.

    Subdomain 1.2: Enroll devices to Microsoft Intune

    5.Intune device limit restrictions can be applied to devices enrolling through Windows Autopilot because each Autopilot enrollment counts individually toward a user's device limit.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: BFalse

    • A. This is incorrect; Windows Autopilot enrollments are explicitly excluded from device limit restrictions.
    • B. Device limit restrictions cannot be applied to Windows Autopilot enrollments because they use shared device mode; a hard limit for these enrollments must instead be configured in Microsoft Entra ID.

    Subdomain 1.2: Enroll devices to Microsoft Intune

    6.To bulk-provision Samsung Android devices out-of-the-box for Intune enrollment, an admin creates a profile in the ___ and adds the Intune enrollment token as custom JSON data.

    1. A.Knox Admin Portal
    2. B.Google zero-touch enrollment portal
    3. C.Apple Business Manager portal
    Show answer & explanation

    Correct answer: AKnox Admin Portal

    • A. The Knox Admin Portal is where a profile is created with Microsoft Intune as the EMM solution and the enrollment token entered as custom JSON data.
    • B. The Google zero-touch enrollment portal is used for Zero Touch configurations, which use a similar JSON structure but is a separate Google-run portal, not the Samsung Knox tool.
    • C. The Apple Business Manager portal manages Apple device enrollment programs and has no role in provisioning Samsung Android devices.

    Subdomain 1.3: Implement identity and compliance

    7.An admin has a role assignment scoped to the Marketing tag, but a newly created compliance policy carries only the default scope tag. The Marketing-scoped admin will be able to see and manage that compliance policy.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: BFalse

    • A. This is incorrect; an admin whose role assignment has a specific scope tag can only see objects that carry a matching tag, and the default tag doesn't match Marketing.
    • B. This is correct; because the policy only carries the default scope tag and not the Marketing tag, an admin scoped to Marketing has no visibility into it until Marketing is added to the policy.

    Subdomain 1.3: Implement identity and compliance

    8.A hospital wants to assign an admin group that can manage device compliance policies, Conditional Access, and Microsoft Defender for Endpoint settings, but should not be able to deploy apps or configuration profiles. Which built-in Intune role fits this admin group?

    1. A.Endpoint Security Manager
    2. B.Policy and Profile Manager
    3. C.Application Manager
    4. D.Help Desk Operator
    Show answer & explanation

    Correct answer: AEndpoint Security Manager

    • A. This role manages security and compliance features such as compliance policy, Conditional Access, and Microsoft Defender for Endpoint integration, matching the hospital's requirement exactly.
    • B. This role manages compliance policy, configuration profiles, Apple enrollment, and security baselines, which goes beyond compliance and Conditional Access into configuration profile deployment.
    • C. This role focuses on managing mobile and managed applications and only has read access to devices, so it doesn't cover compliance policy or Conditional Access management.
    • D. This role performs remote tasks and assigns existing apps or policies to users and devices, but it isn't intended for authoring compliance or Conditional Access configuration.

    Subdomain 1.3: Implement identity and compliance

    9.Which limitation should an admin account for when using the Conditional Access compliant network location condition together with Intune compliance?

    1. A.It is only supported for devices already enrolled in MDM, so unenrolled devices can be unexpectedly blocked unless excluded
    2. B.It only evaluates network location during the first sign-in after enrollment and never again afterward
    3. C.It requires every device to have a Windows LAPS policy assigned before the condition can evaluate correctly
    4. D.It disables app-based Conditional Access policies for any user included in the same policy
    Show answer & explanation

    Correct answer: AIt is only supported for devices already enrolled in MDM, so unenrolled devices can be unexpectedly blocked unless excluded

    • A. This condition is documented as only reliably supported for MDM-enrolled devices, so users on unenrolled devices should be excluded to avoid being unintentionally blocked.
    • B. The condition isn't limited to a one-time evaluation at first sign-in; it's evaluated as part of ongoing Conditional Access decisions, not just a single initial check.
    • C. There is no dependency between Windows LAPS policy assignment and the compliant network location condition; the two features operate independently of each other.
    • D. Using this condition doesn't disable app-based Conditional Access for anyone; device-based and app-based policies operate as separate, coexisting mechanisms.

    Domain 2: Manage and maintain devices

    Subdomain 2.1: Deploy and upgrade Windows clients by using cloud-based tools

    10.An organization has thousands of Windows 10 devices that meet Windows 11 hardware requirements and wants to control the exact Windows 11 version offered along with a scheduled rollout start date. Which Intune capability accomplishes this?

    1. A.A feature update deployment profile that specifies the target Windows 11 version and rollout schedule
    2. B.A quality update deployment profile that installs monthly cumulative updates
    3. C.A device configuration profile that enables the Windows Insider Program
    4. D.An app deployment policy that pushes the Windows 11 installer as a Win32 app
    Show answer & explanation

    Correct answer: AA feature update deployment profile that specifies the target Windows 11 version and rollout schedule

    • A. A feature update deployment profile is the Intune policy type that names a target Windows 11 version and controls when it starts rolling out to targeted devices.
    • B. Quality update profiles handle monthly cumulative security and reliability patches within the current Windows version, not the upgrade to a new feature version like Windows 11.
    • C. Enabling the Windows Insider Program targets pre-release builds for testing purposes and is not the supported mechanism for a controlled production upgrade rollout.
    • D. Pushing the installer as a Win32 app bypasses the built-in feature update servicing controls, such as safeguard holds and staged rollout, that the dedicated profile provides.

    Subdomain 2.1: Deploy and upgrade Windows clients by using cloud-based tools

    11.A warehouse deploys ruggedized handheld scanners that rotate between many different workers each shift, and no single worker should be tied to a device. The administrator should configure Windows Autopilot ___ mode for these devices.

    1. A.self-deploying
    2. B.user-driven
    3. C.pre-provisioning
    Show answer & explanation

    Correct answer: Aself-deploying

    • A. This mode fits shared, rotating-use devices because it deliberately avoids tying the device to any one user and can run with minimal interaction.
    • B. This mode expects a single person to sign in with their own credentials during setup, which conflicts with devices meant to rotate between many different workers.
    • C. This mode still results in a device configured for eventual use by an assigned worker, and it adds a technician setup step that isn't needed for shared shift-rotation scanners.

    Subdomain 2.1: Deploy and upgrade Windows clients by using cloud-based tools

    12.An administrator has deployed a settings catalog policy that enables Windows Backup on managed devices. Before end users can actually restore their settings on a new device, the administrator must also enable the restore experience at the ___ level.

    1. A.tenant
    2. B.device
    3. C.individual app
    Show answer & explanation

    Correct answer: Atenant

    • A. Enabling Windows Backup for Organizations is a two-step process, and the second step is enabling the restore page at this broader organizational scope, not per device.
    • B. The restore experience is not toggled per individual device; it is enabled at a broader scope that applies across the organization once the settings catalog policy is in place.
    • C. There is no per-app restore toggle required for this feature; the second configuration step operates at a broader organizational scope, not at the level of a single app.

    Subdomain 2.2: Plan and implement device configuration profiles

    13.An admin at Contoso wants to move a fleet of Azure AD-joined Windows 11 devices away from on-premises Group Policy. They export several GPOs from the Group Policy Management Console and need to see which settings already have an Intune equivalent before building a Settings Catalog policy. Which tool should the admin use first?

    1. A.Group Policy analytics
    2. B.Endpoint security baselines
    3. C.Windows Autopilot deployment profiles
    4. D.Conditional Access policies
    Show answer & explanation

    Correct answer: AGroup Policy analytics

    • A. Group Policy analytics imports the exported GPO XML report and compares each setting against Intune's supported CSPs, showing an MDM Support percentage before any migration work begins.
    • B. Security baselines apply Microsoft-recommended preconfigured setting groups; they do not import or analyze existing on-premises Group Policy objects.
    • C. Autopilot deployment profiles control the out-of-box provisioning experience for new devices and play no role in analyzing legacy Group Policy settings.
    • D. Conditional Access enforces sign-in and access controls based on identity and device signals; it does not import or evaluate Group Policy objects.

    Subdomain 2.2: Plan and implement device configuration profiles

    14.An admin needs to configure a web content filter and lock the Home Screen layout on school-owned iPads enrolled through Automated Device Enrollment. Which condition must be true for these restriction settings to take effect?

    1. A.The devices must be enrolled as supervised
    2. B.The devices must be jailbroken for testing purposes
    3. C.The devices must run exclusively in Shared iPad mode
    4. D.The devices must have Find My iPhone turned off
    Show answer & explanation

    Correct answer: AThe devices must be enrolled as supervised

    • A. Web content filtering and Home Screen layout restrictions are supervised-only settings, so the iPads must be enrolled as supervised devices, which Automated Device Enrollment enables by default.
    • B. Jailbreaking removes Apple's management protections entirely and would prevent Intune from applying any configuration profile, so it is never a requirement.
    • C. Shared iPad mode supports multiple signed-in users on one device and is unrelated to whether supervised-only restrictions like Home Screen layout locking are available.
    • D. Find My iPhone status affects Activation Lock behavior during wipe and reset, not whether supervised restriction settings can be applied to the device.

    Subdomain 2.2: Plan and implement device configuration profiles

    15.The Administrative Templates profile type under Templates is deprecated and read-only, but importing custom ADMX files for use in the settings catalog is still supported.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: ATrue

    • A. Since the December 2412 release, the legacy Administrative Templates profile type is deprecated and read-only, while custom and partner ADMX/ADML import remains supported for use through the settings catalog.
    • B. This is not false; the deprecation applies specifically to the older Templates profile type, and custom ADMX import continues to work through the newer settings catalog path.

    Subdomain 2.3: Implement Intune Suite add-on capabilities

    16.A traveling executive's laptop is frozen at the sign-in screen and no one is available to accept a help request. A technician needs to sign in with their own credentials to troubleshoot without the executive present. Which Remote Help capability should the technician use?

    1. A.Unattended remote sign-in
    2. B.Remote launch
    3. C.Web app sharer mode
    4. D.Conditional Access elevation
    Show answer & explanation

    Correct answer: AUnattended remote sign-in

    • A. This is correct because it lets an authorized helper sign in to a corporate Windows device with their own credentials and troubleshoot without requiring an end user to be present or signed in.
    • B. This is incorrect because this capability launches Remote Help on the sharer's device by sending a notification, which still depends on the sharer's session and does not work when no one is present to accept it.
    • C. This is incorrect because this mode lets a sharer who cannot install the native app share their screen through a browser, but it still requires the sharer to be present and participating.
    • D. This is incorrect because Conditional Access controls how helpers and sharers authenticate into a session but is not itself a mechanism for starting an unattended sign-in.

    Subdomain 2.3: Implement Intune Suite add-on capabilities

    17.While capacity planning for certification authorities, an admin notes: "An Intune tenant can create a maximum of ___ certification authorities using Microsoft Cloud PKI, whether licensed or in trial."

    1. A.three
    2. B.five
    3. C.ten
    Show answer & explanation

    Correct answer: Athree

    • A. This is correct because both licensed and trial Cloud PKI deployments are capped at this number of certification authorities per tenant, counting root, issuing, and bring-your-own CAs.
    • B. This is incorrect because it exceeds the documented per-tenant limit for Cloud PKI certification authorities.
    • C. This is incorrect because it is well above the documented per-tenant limit for Cloud PKI certification authorities.

    Subdomain 2.3: Implement Intune Suite add-on capabilities

    18.After a driver update rolls out, an admin notices a spike in unexplained restarts across a subset of laptops and wants to compare Stop Error Restart counts on the same devices before and after the driver update to see whether the difference is statistically significant. Which anomaly detection model fits this comparison?

    1. A.Paired t-tests model
    2. B.Threshold-based heuristic model
    3. C.Population Z-score model
    4. D.Time series Z-score model
    Show answer & explanation

    Correct answer: APaired t-tests model

    • A. This is correct because this model compares pairs of observations, such as the same device's Stop Error Restarts before and after a change, to test whether the difference in their means is statistically significant.
    • B. This is incorrect because this model simply flags devices that breach a predetermined threshold and does not compare before-and-after values for the same devices.
    • C. This is incorrect because this model looks for outliers across a population using standard deviation from the mean, rather than comparing paired before-and-after measurements on the same devices.
    • D. This is incorrect because this model adapts a Z-score calculation to a sliding time window to catch trend changes, rather than directly pairing pre- and post-change values on the same devices.

    Subdomain 2.4: Perform remote actions on devices

    19.An admin submits a Wipe request for a Windows device that already has a pending Sync and a pending Restart queued. What happens the next time the device checks in?

    1. A.Only the Wipe action runs on the device; the Sync and Restart requests are dropped
    2. B.All three actions run in sequence in the order they were originally submitted
    3. C.The Restart runs first since it was queued earliest, and the Wipe follows afterward
    4. D.The device applies Sync and Restart first, and Wipe is queued for the following cycle
    Show answer & explanation

    Correct answer: AOnly the Wipe action runs on the device; the Sync and Restart requests are dropped

    • A. Wipe takes precedence over all other pending actions, so when it's queued alongside Sync and Restart, only the Wipe executes and the other requests are ignored.
    • B. Intune doesn't queue and run every pending action in submission order once a Wipe, Retire, or Delete is present - those three override anything else pending.
    • C. Order of submission doesn't determine execution here; Wipe overrides earlier-queued actions like Restart rather than running after them.
    • D. Sync and Restart aren't processed ahead of a pending Wipe - the Wipe takes priority and runs instead of the other two.

    Subdomain 2.4: Perform remote actions on devices

    20.An admin collects diagnostics from a device on day 1, then checks back on day 40 hoping to download the same package. The download fails because collections are only retained for ___.

    1. A.28 days
    2. B.90 days
    3. C.7 days
    Show answer & explanation

    Correct answer: A28 days

    • A. Diagnostic collections are stored for 28 days and then automatically deleted, so a package requested on day 1 is no longer available by day 40.
    • B. This retention period is longer than what Intune actually keeps diagnostic collections for, so it doesn't match the observed failure.
    • C. This retention period is shorter than what Intune actually keeps diagnostic collections for; the package would still have been available well past 7 days.

    Domain 3: Protect devices

    Subdomain 3.1: Configure endpoint security

    21.Before an EDR policy can offer the Auto from connector onboarding option, an admin must first establish the service-to-service connection under Tenant administration > ___.

    1. A.Connectors and tokens
    2. B.Role-based access control
    3. C.Scope tags
    Show answer & explanation

    Correct answer: AConnectors and tokens

    • A. This is where the Microsoft Defender for Endpoint connection is enabled and verified, and only once it shows Connected does the Auto from connector option become available in EDR policies.
    • B. This area manages permission assignments for administrators and has no role in establishing the Defender for Endpoint service connection.
    • C. Scope tags control which admins can see and manage specific policies, but they don't establish or verify the connector needed for automatic onboarding packages.

    Subdomain 3.1: Configure endpoint security

    22.An admin creates an App Control for Business base policy using built-in controls, trusting Windows components and apps from the managed installer. They now need extra custom rules layered on top of this same base policy for just one department. What should they create?

    1. A.A supplemental policy in XML format that references the base policy's Policy ID
    2. B.A second, independent base policy that generates its own new Policy ID
    3. C.A device configuration Endpoint protection profile that duplicates the same app rules
    4. D.A managed installer policy scoped only to that department's device group
    Show answer & explanation

    Correct answer: AA supplemental policy in XML format that references the base policy's Policy ID

    • A. A supplemental policy is built for exactly this purpose, expanding an existing base policy's circle of trust for a specific group without disturbing the base policy used elsewhere.
    • B. Creating an unrelated second base policy would give that department a completely separate ruleset instead of extending the base policy already in place for everyone else.
    • C. Device configuration profiles don't use the ApplicationControl CSP that App Control for Business relies on, so duplicating rules there wouldn't extend the existing base policy at all.
    • D. A managed installer policy only controls whether Intune-deployed apps get tagged as trusted; it can't add custom app rules on top of an existing base policy.

    Subdomain 3.2: Manage device updates

    23.An admin at Contoso pauses a Windows update ring to test a problematic driver. True or False: the pause automatically expires after 35 days if the admin takes no further action.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: ATrue

    • A. Pausing a ring prevents assigned devices from receiving feature or quality updates for up to 35 days from the time the pause is issued. After that maximum, the pause automatically expires and devices scan for applicable updates again.
    • B. This statement understates the actual behavior, since the pause does expire automatically rather than continuing indefinitely. The admin would need to select Extend before the 35 days elapse to keep the pause active longer.

    Subdomain 3.2: Manage device updates

    24.True or False: devices managed by Windows Autopatch should typically be assigned custom update ring policies to override the deferral settings that the Autopatch service manages.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: BFalse

    • A. This overstates what's recommended, since admins are typically advised not to assign custom update rings on top of Autopatch-managed devices. Doing so can conflict with the rollout cadence and restart behavior the service is already orchestrating.
    • B. When devices are managed through Windows Autopatch, update rings may be created and maintained by the service itself to implement rollout cadence and restart behavior. Admins typically shouldn't assign custom update rings to Autopatch-managed devices, since custom rings work in combination with, not as a replacement for, service-managed policies.

    Subdomain 3.2: Manage device updates

    25.A retailer wants firmware updates for its Samsung Android checkout tablets managed through Intune. This is achieved by integrating with ______.

    1. A.Samsung Knox E-FOTA
    2. B.Zebra LifeGuard
    3. C.Windows Autopatch
    Show answer & explanation

    Correct answer: ASamsung Knox E-FOTA

    • A. Samsung Knox E-FOTA integration is the manufacturer-specific mechanism Intune supports for managing firmware-over-the-air updates on Samsung Android devices, offering more controls than generic device restriction profiles alone.
    • B. Zebra LifeGuard Over-the-Air integration manages firmware updates for Zebra devices specifically, not Samsung hardware, so it wouldn't apply to this retailer's Samsung tablets.
    • C. Windows Autopatch manages Windows update deployment and has no role in managing firmware updates for Android devices from any manufacturer.

    Domain 4: Manage and secure applications

    Subdomain 4.1: Deploy and update apps

    26.An app assigned with the "Available for enrolled devices" intent will automatically reinstall itself if a user manually uninstalls it from their device.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: BFalse

    • A. This is incorrect because apps installed through the Available intent are user-initiated and are not automatically reinstalled by Intune after removal.
    • B. This is correct because Win32 apps installed using the Available for enrolled devices intent will not be automatically reinstalled once a user removes them.

    Subdomain 4.1: Deploy and update apps

    27.Microsoft Intune supports interactive application installations that display prompts or require user input during a Win32 app installation.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: BFalse

    • A. This is incorrect because Intune requires silent installations for Win32 apps and does not support techniques that force interaction with the signed-in user session.
    • B. This is correct because Microsoft explicitly states that applications deployed through Intune must install silently, without dialog boxes, prompts, or other UI interaction.

    Subdomain 4.1: Deploy and update apps

    28.The Microsoft 365 Apps admin center's cloud update capability lets admins move devices between update channels using channel profiles without repackaging or redeploying the Office installer.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: ATrue

    • A. This is correct because cloud update lets admins group devices into servicing or channel profiles and change their update channel centrally, without touching the original app package.
    • B. This is incorrect because channel migration through cloud update is designed to avoid repackaging; it is managed centrally through profiles rather than by redeploying installers.

    Subdomain 4.2: Plan and implement app protection and app configuration policies

    29.A company wants to use Intune app protection policies to protect the Outlook mobile app for users whose mailboxes remain on an on-premises Exchange server. Which configuration is required for this to work?

    1. A.Exchange Server configured with hybrid Modern Authentication
    2. B.A device compliance policy targeting the Exchange ActiveSync profile
    3. C.An app configuration policy setting the mailbox to cached mode
    4. D.Migrating the mailbox to Exchange Online before applying any policy
    Show answer & explanation

    Correct answer: AExchange Server configured with hybrid Modern Authentication

    • A. Outlook for iOS/iPadOS and Android only supports Intune app protection for on-premises Exchange mailboxes when hybrid Modern Authentication is enabled, which is the requirement for this scenario.
    • B. A device compliance policy relates to device-based Conditional Access, not to whether Outlook can receive app protection policies for an on-premises mailbox.
    • C. Cached mode is a mailbox synchronization setting and has no bearing on whether Outlook app protection policies can be enforced against an on-premises Exchange mailbox.
    • D. Migrating the mailbox to Exchange Online is unnecessary, since app protection for Outlook can be supported against on-premises Exchange specifically when hybrid Modern Authentication is configured.

    Subdomain 4.2: Plan and implement app protection and app configuration policies

    30.In an app-based Conditional Access policy, selecting Require approved client app together with ___ under Grant access controls ensures that only apps enforcing Intune app protection policies can access company data.

    1. A.Require app protection policy
    2. B.Require multifactor authentication
    3. C.Require hybrid Microsoft Entra joined device
    Show answer & explanation

    Correct answer: ARequire app protection policy

    • A. Require app protection policy is the grant control that specifically checks whether the client app is enforcing an app protection policy, completing the app-based Conditional Access combination.
    • B. Multifactor authentication strengthens sign-in verification but does not check whether the client app enforces app protection policies.
    • C. Requiring a hybrid Microsoft Entra joined device is a device-based control for domain-joined Windows devices, not part of the app-based combination described here.

    Domain 5: Optimize endpoint operations by using automation, monitoring, and reporting

    Subdomain 5.1: Automate management tasks

    31.A custom compliance report shows error code 65008 for a Windows device. What does this code indicate?

    1. A.The discovery script itself returned a failure exit code
    2. B.A setting defined in the JSON file is missing from the script's output
    3. C.The JSON returned by the script uses an invalid format
    4. D.A discovered setting's value uses an unsupported data type
    Show answer & explanation

    Correct answer: BA setting defined in the JSON file is missing from the script's output

    • A. A script failure is reported under a different code that reflects the script itself failing to run, not a missing setting in otherwise successful output.
    • B. This code specifically flags that a setting the JSON file expects wasn't present in what the discovery script returned, which is the scenario described.
    • C. Malformed JSON from the script is captured by a separate code focused on the output not being valid JSON, not a missing setting.
    • D. An unsupported data type for a discovered setting is reported under its own distinct code, separate from a setting being absent altogether.

    Subdomain 5.1: Automate management tasks

    32.Custom compliance settings in Intune require a discovery script and a ___ file that defines the settings and the values considered compliant.

    1. A.XML
    2. B.JSON
    3. C.YAML
    Show answer & explanation

    Correct answer: BJSON

    • A. XML is not the format Intune expects for defining custom compliance settings and their compliant values.
    • B. JSON is the format used to define each custom setting along with the operator, data type, and value considered compliant.
    • C. YAML isn't a format Intune parses for custom compliance settings; the platform expects the setting definitions in a different structured format.

    Subdomain 5.2: Monitor and optimize health

    33.An administrator is reviewing how the Intune Management Extension retrieves and reports remediation script results for a recurring, daily-scheduled script package. Which statements about this behavior are correct? (Select all that apply.)(Select 3)

    1. A.The client checks for new remediation policy after a restart of the device or the management extension service
    2. B.The client also checks for new remediation policy once every 8 hours regardless of user sign-in activity
    3. C.For a recurring script, the client sends a result report only when the output changes during the first six days
    4. D.The client discards remediation results if the device is offline and never reports them once it reconnects
    5. E.Recurring scripts always report a completely fresh result within an hour of every single script execution
    Show answer & explanation

    Correct answers: A, B, CThe client checks for new remediation policy after a restart of the device or the management extension service; The client also checks for new remediation policy once every 8 hours regardless of user sign-in activity; For a recurring script, the client sends a result report only when the output changes during the first six days

    • A. Policy retrieval is triggered after a device restart or a restart of the Intune Management Extension service, which is one of the documented retrieval triggers.
    • B. The client also checks for policy on a fixed 8-hour cycle tied to when the management extension service starts, independent of whether a user has signed in.
    • C. Recurring scripts follow a seven-day reporting cycle where, within the first six days, the client only reports a result if something changed from the previous run.
    • D. Offline devices still report their remediation results once they come back online and can communicate with Intune again; results are not permanently discarded.
    • E. Recurring scripts only guarantee a report even without a change once every seven days, not within an hour of every execution, so results are not always immediate.

    Subdomain 5.2: Monitor and optimize health

    34.Which of the following correctly describe when a connector on the Intune tenant status page is marked as Unhealthy? (Select all that apply.)(Select 2)

    1. A.Its certificate or credential has already expired and was not renewed in time for this connector
    2. B.Its last successful synchronization with Intune occurred three or more days ago
    3. C.Its certificate or credential will expire within the next seven calendar days starting from today
    4. D.It has never been configured by an administrator for this Intune tenant at any point
    5. E.Its last successful synchronization with Intune occurred more than one day ago
    Show answer & explanation

    Correct answers: A, BIts certificate or credential has already expired and was not renewed in time for this connector; Its last successful synchronization with Intune occurred three or more days ago

    • A. An already-expired certificate or credential is one of the two documented conditions that mark a connector as Unhealthy.
    • B. A synchronization gap of three or more days is the other documented condition that marks a connector as Unhealthy.
    • C. A credential expiring within seven days places the connector in the Warning state, not Unhealthy, since it has not expired yet.
    • D. A connector that has never been configured is shown as Not Enabled, a separate state from Unhealthy, which applies only to configured connectors with a problem.
    • E. A synchronization gap of more than one day but less than three days places the connector in the Warning state, not Unhealthy.

    Subdomain 5.2: Monitor and optimize health

    35.A remediation script package can be created with a detection script only, and no remediation script.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: ATrue

    • A. A script package can contain a detection script by itself, useful for reporting on an issue without automatically fixing it, or it can pair the detection script with a remediation script.
    • B. This statement is true, so False does not apply here.

    Want the full experience?

    These are just samples. Practice the full Microsoft Certified: Endpoint Administrator Associate (MD-102) question bank in quiz mode — free, no signup, with domain practice and exam simulation.