57 Practice Questions & Answers
You need to configure Windows Update for Business settings across multiple devices in your organization. Which feature allows you to defer feature and quality updates for specific periods?
-
A
Windows Server Update Services (WSUS)
-
B
Windows Update Medic Service
-
C
Delivery Optimization
-
D
Update rings for Windows 10 and later
✓ Correct
Explanation
Update rings in Intune allow administrators to define deployment schedules and deferral periods for Windows updates across groups of devices. This is the primary Intune mechanism for managing Windows Update for Business.
A user's device fails to enroll in Intune. You check the enrollment restrictions and find that the device ownership type is blocked. What enrollment restriction setting controls which device ownership types can enroll?
-
A
Platform restrictions
-
B
User enrollment limitations
-
C
Device type restrictions
-
D
Device ownership restrictions
✓ Correct
Explanation
Device ownership restrictions determine whether personally owned devices (BYOD) or corporate-owned devices can enroll in Intune. This is a key enrollment policy setting.
You want to ensure that corporate devices cannot be used for personal purposes. Which compliance policy setting should you configure to verify that the device is registered as a corporate-owned device?
-
A
Device classification enforcement
-
B
Device ownership requirement
✓ Correct
-
C
Personally-owned device detection
-
D
Corporate device verification
Explanation
The device ownership requirement compliance setting allows you to enforce that only devices marked as corporate-owned can remain compliant with your organization's policies.
Your organization requires strong password policies on all managed devices. You create a device compliance policy requiring passwords of at least 8 characters with complexity requirements. What happens to a device that fails this compliance check?
-
A
The user receives a warning but can continue working indefinitely
-
B
The device is marked as noncompliant and conditional access policies are evaluated
✓ Correct
-
C
The device loses all network connectivity immediately
-
D
The device is automatically wiped
Explanation
When a device fails compliance, it is marked as noncompliant and Azure AD conditional access policies determine what actions occur (such as blocking access to corporate resources). Automatic actions like wiping require explicit configuration.
You are configuring mobile application management (MAM) for iOS devices that are not enrolled in Intune. Which authentication method should users employ to establish the initial MAM policy?
-
A
Windows Hello for Business
-
B
Azure AD enrollment
-
C
FIDO2 security keys
-
D
Microsoft Authenticator or Company Portal app installation
✓ Correct
Explanation
For unenrolled iOS devices, users authenticate through the Company Portal or Microsoft Authenticator app, which enables MAM policies to be applied without full device enrollment.
An administrator wants to restrict which cloud storage services employees can use on their managed devices. Which Intune policy type is best suited for this requirement?
-
A
App configuration policy
-
B
Application protection policy
✓ Correct
-
C
Compliance policy
-
D
Device configuration profile
Explanation
Application protection policies (MAM) can restrict data movement to unmanaged cloud storage services, controlling where corporate data can be saved or shared from managed apps.
You need to deploy certificates to devices for authentication purposes. Which Intune profile type should you use to distribute trusted root and intermediate certificates?
-
A
Trusted certificate profile
✓ Correct
-
B
WiFi profile
-
C
VPN profile
-
D
SCEP certificate profile
Explanation
Trusted certificate profiles distribute root and intermediate CA certificates to devices to establish certificate chains for authentication and secure communications.
Your organization uses a hybrid Azure AD joined environment. When a user attempts to reset their password using Windows, which service must be available for the password reset to succeed?
-
A
Active Directory Domain Services
-
B
Azure AD Password Reset Service and on-premises domain controller connectivity
✓ Correct
-
C
Local SAM database only
-
D
Windows Server Update Services
Explanation
In hybrid Azure AD joined scenarios, Windows Password Reset requires communication with both Azure AD for verification and on-premises domain controllers to update the password.
You want to prevent users from installing applications from the Microsoft Store on corporate Windows 11 devices. Which configuration method is most appropriate?
-
A
Device configuration profile restricting Store access
-
B
Application control policies using AppLocker
✓ Correct
-
C
Conditional access policy
-
D
Compliance policy blocking noncompliant apps
Explanation
AppLocker can be configured through device configuration profiles to restrict or block the Microsoft Store application and control software installation on Windows devices.
A device is marked as noncompliant due to a missing security update. The user contacts support and confirms they have applied the update. What should the endpoint administrator check first to resolve the compliance status?
-
A
Force the device to sync with Intune to refresh compliance evaluation
✓ Correct
-
B
Remove the device from Intune management
-
C
Review the device's last check-in time with Intune
-
D
Immediately wipe the device
Explanation
Devices must sync with Intune to report their current status. Forcing a sync will trigger a fresh compliance evaluation reflecting the applied security update.
Your organization requires that all corporate data on personal devices be wiped if the device is no longer managed. Which MAM policy setting enables this capability?
-
A
Restrict cut, copy, and paste
-
B
Allow backup to cloud
-
C
Wipe corporate data when device unenrolls
✓ Correct
-
D
Require device encryption
Explanation
The 'Wipe corporate data when device unenrolls' setting in app protection policies ensures that managed corporate data is removed if the device is no longer under management.
You are configuring Autopilot for a large group of devices. The organization needs devices to join Azure AD but does NOT want to join on-premises Active Directory. Which Autopilot mode should you select?
-
A
Hybrid Azure AD join mode
-
B
Self-deploying mode
-
C
On-premises domain join mode
-
D
User-driven mode with Azure AD join
✓ Correct
Explanation
User-driven mode with Azure AD join allows devices to enroll directly into Azure AD without requiring on-premises Active Directory domain join during Autopilot.
An administrator creates a device configuration profile with settings for password requirements. After assigning it to 100 devices, only 50 devices report compliance. What is the most likely reason?
-
A
The administrator lacks permissions to assign policies
-
B
Some devices may not have checked in yet or have encountered conflicts with other policies
✓ Correct
-
C
The assignment was incomplete
-
D
Windows has cached the old policy settings
Explanation
Devices require time to sync with Intune, and policy conflicts or incompatibilities may prevent some devices from adopting the configuration. Checking device sync status and policy conflicts would diagnose the issue.
You need to configure a VPN connection that uses certificate-based authentication. Which Intune profile type should you deploy?
-
A
Device restriction profile
-
B
WiFi configuration profile
-
C
Email configuration profile
-
D
VPN profile with SCEP certificate
✓ Correct
Explanation
A VPN profile combined with a SCEP certificate profile enables certificate-based authentication for VPN connections, with the certificate automatically deployed and renewed.
Your organization wants to allow personal device usage while protecting corporate data. Users will access corporate resources through the Company Portal and managed apps. Which approach best describes this scenario?
-
A
Hybrid device registration
-
B
Conditional access enforcement
-
C
Mobile application management (MAM) only
✓ Correct
-
D
Full device management (MDM)
Explanation
MAM without device enrollment allows corporate data protection through managed apps on personal devices without managing the entire device, which is ideal for BYOD scenarios.
You deploy a configuration profile that blocks the use of external USB drives on Windows devices. A few users report that their USB drives still function. What is a likely cause?
-
A
USB drivers were not updated
-
B
External USB is a hardware feature that cannot be controlled by software
-
C
The profile may not have applied due to policy conflicts or the device using a legacy USB controller driver
✓ Correct
-
D
The user has administrative privileges that override the policy
Explanation
Policy conflicts or incompatible hardware drivers can prevent device restriction policies from applying correctly. Device conflict reports and policy evaluation logs would reveal the root cause.
An administrator configures a compliance policy requiring encrypted storage. A Windows device reports as compliant even though encryption is disabled. What should the administrator verify first?
-
A
The device has the latest Windows updates
-
B
The grace period for the compliance policy has not expired
-
C
The device's TPM firmware is updated
-
D
The encryption standard (BitLocker) is properly configured and reporting
✓ Correct
Explanation
Compliance evaluation relies on accurate device reporting. The administrator should verify that BitLocker is actually enabled and reporting its status correctly to Intune's compliance engine.
You want to deploy Microsoft Edge with specific security settings to all managed devices. What is the most efficient method to configure Edge settings at scale?
-
A
Manual installation on each device
-
B
Microsoft Store deployment only
-
C
Intune app configuration policy for Microsoft Edge
✓ Correct
-
D
Group Policy Objects in Active Directory
Explanation
Intune app configuration policies allow you to deploy and manage Edge settings at scale across all managed devices, including cloud-only and hybrid scenarios.
A user's corporate-owned Windows device is lost. What is the first action an endpoint administrator should take to protect company data?
-
A
Issue a remote wipe command through Intune
✓ Correct
-
B
Reset the user's Azure AD password
-
C
Wait for the user to report the device before taking action
-
D
Disable the device object in Active Directory only
Explanation
Immediately issuing a remote wipe command through Intune removes corporate data from the lost device before it can be accessed by an unauthorized user.
Your organization implements conditional access policies that require device compliance for accessing Microsoft 365. A compliant device suddenly loses access. What is the most probable cause?
-
A
Microsoft 365 licensing was revoked
-
B
The device exceeded its storage limit
-
C
The device missed a compliance check-in and is now marked noncompliant
✓ Correct
-
D
The user's Azure AD group membership was removed
Explanation
If a previously compliant device misses check-ins or fails a compliance evaluation, it becomes noncompliant and the conditional access policy blocks access to Microsoft 365 resources.
An administrator needs to ensure that sensitive corporate documents are watermarked when opened on any device. Which solution best addresses this requirement?
-
A
Conditional access policy
-
B
Compliance policy
-
C
Azure Information Protection (AIP) labels with watermarking
✓ Correct
-
D
Device configuration profile
Explanation
Azure Information Protection labels with visual markings (watermarks) can be configured to automatically watermark sensitive documents when opened, regardless of device type.
You are configuring Windows Autopilot for hybrid Azure AD join in a corporate environment. Which service role must be configured on-premises to support the domain join during Autopilot?
-
A
Active Directory Federation Services (ADFS)
-
B
Network Policy Server (NPS)
-
C
WSUS server
-
D
Azure AD Connect configured for password hash synchronization or pass-through authentication
✓ Correct
Explanation
Azure AD Connect must be properly configured to synchronize identity data and support authentication during the hybrid join process in Autopilot scenarios.
A compliance policy requires that devices have antivirus software from a specific vendor installed. What type of compliance rule should be configured?
-
A
Antivirus compliance rule
-
B
Advanced threat protection setting
-
C
Threat and vulnerability management
-
D
System security setting
✓ Correct
Explanation
System security settings in compliance policies allow verification that specific security software (such as particular antivirus vendors) is installed and functioning.
You need to enroll Windows 10 devices into Microsoft Intune. Which enrollment method is most appropriate for BYOD (Bring Your Own Device) scenarios?
-
A
Windows Autopilot
-
B
User self-enrollment through the Company Portal
✓ Correct
-
C
Azure AD join during OOBE
-
D
Group Policy enrollment
Explanation
Self-enrollment through Company Portal is the standard method for BYOD scenarios as it allows users to enroll their personal devices without IT intervention. Windows Autopilot and Azure AD join are typically used for corporate devices.
What is the primary purpose of Windows Autopilot in endpoint management?
-
A
To enforce disk encryption on all endpoints
-
B
To automatically patch Windows devices
-
C
To simplify and streamline device deployment by transforming new devices into corporate-ready endpoints with minimal IT involvement
✓ Correct
-
D
To manage application licenses across the organization
Explanation
Windows Autopilot simplifies device deployment by allowing pre-configured devices to be shipped directly to users, who then follow a guided setup process. The device is automatically enrolled and configured according to organizational policies.
You are configuring Conditional Access policies in Azure AD for Intune-enrolled devices. Which condition would require a device to be marked as compliant before allowing access to company resources?
-
A
Device state condition set to 'Compliant'
✓ Correct
-
B
Application condition targeting Microsoft 365 apps
-
C
User risk level set to 'High'
-
D
Location condition restricted to corporate networks
Explanation
The 'Device state' condition in Conditional Access allows administrators to require devices to be marked as compliant according to defined compliance policies. This ensures only devices meeting security standards can access resources.
A user's Windows 10 device fails a compliance check because the antivirus definition file is outdated. What is the primary remediation action that Intune can take automatically?
-
A
Unroll the device from Intune management
-
B
Wipe the device remotely
-
C
Block access to company resources and notify the user to update the antivirus definitions
✓ Correct
-
D
Force a device restart to trigger antivirus updates
Explanation
When a device fails compliance, Intune marks it as non-compliant, which triggers Conditional Access policies to block access. Users receive notifications to remediate the issue. Device wipe is a more severe action applied in specific scenarios, not automatically.
You need to deploy a line-of-business (LOB) application to 500 managed devices using Intune. The application requires administrative privileges to install. Which deployment method is most suitable?
-
A
System-context deployment using a device configuration profile with elevated rights
✓ Correct
-
B
Device-context deployment with administrative privileges in the app protection policy
-
C
Direct installation through Group Policy on domain-joined devices only
-
D
User-context application assignment through Company Portal
Explanation
Device-context (system-context) deployment allows applications to be installed with administrative privileges on managed devices. This is ideal for LOB applications requiring elevated permissions that users cannot install themselves.
What is the primary benefit of using Mobile Application Management (MAM) without Mobile Device Management (MDM)?
-
A
It provides complete control over all device settings and features
-
B
It allows offline access to all company resources indefinitely
-
C
It eliminates the need for any authentication mechanism on mobile devices
-
D
It protects corporate data within applications without requiring full device enrollment or ownership
✓ Correct
Explanation
MAM-only policies protect corporate data at the application level without requiring device enrollment, making it ideal for BYOD scenarios where IT doesn't manage the entire device. Users can still use personal apps and settings.
You are implementing device compliance policies for iOS devices. Which setting would prevent users from jailbroken devices from accessing company email through Outlook?
-
A
Disabling Bluetooth on all iOS devices through device configuration
-
B
Setting 'Jailbreak detection' to 'Block' in the compliance policy
✓ Correct
-
C
Enabling two-factor authentication for all Outlook access
-
D
Requiring a minimum OS version of iOS 14 or later
Explanation
The jailbreak detection setting in iOS compliance policies specifically identifies compromised devices and marks them as non-compliant. Combined with Conditional Access, this blocks access to company resources like email.
A department requires a VPN connection to be active before users can access internal applications on their Windows 10 devices. How should this be configured in Intune?
-
A
Create a device compliance policy requiring active VPN with a specific VPN profile
-
B
Use only Group Policy to mandate VPN connections for all network access
-
C
Deploy a VPN profile and create a device configuration profile that enforces the VPN connection before network access is allowed
✓ Correct
-
D
Deploy a VPN profile and configure Conditional Access to require a compliant device state
Explanation
A VPN profile deployment combined with device configuration ensures the VPN is installed and configured. To enforce it before access, configure it at the network level in device configuration or use compliance policies that check for active VPN status.
Which role in Intune has the minimum permissions required to enroll devices and assign applications but cannot modify compliance policies or conditional access?
-
A
Compliance Manager
-
B
Application Manager
✓ Correct
-
C
Intune Administrator
-
D
Endpoint Security Manager
Explanation
The Application Manager role is limited to application assignment and management. It does not include permissions for compliance policies, conditional access, or device enrollment configurations.
You need to configure BitLocker encryption for Windows 10 devices in your organization. What is the recommended approach using Intune?
-
A
Deploy a compliance policy that audits BitLocker status without enforcing encryption
-
B
Manually enable BitLocker on each device through Settings
-
C
Use Group Policy exclusively on domain-joined devices only
-
D
Deploy a device configuration profile with BitLocker settings for Windows 10 devices
✓ Correct
Explanation
A device configuration profile allows centralized deployment of BitLocker settings to Windows 10 devices in Intune, ensuring consistent encryption across the organization regardless of domain join status.
An organization wants to allow users to access cloud apps from non-compliant devices but log and monitor such access for security auditing. Which Conditional Access control is most appropriate?
-
A
Require password change before access
-
B
Grant access only during business hours
-
C
Block access immediately
-
D
Require multi-factor authentication and session controls with monitoring
✓ Correct
Explanation
Session controls in Conditional Access allow monitoring and logging of access from non-compliant devices while permitting the connection. Multi-factor authentication adds an additional security layer without blocking access entirely.
What is the primary function of the Intune admin center's 'Devices' section?
-
A
To create and assign applications to user groups
-
B
To manage billing and subscription licenses
-
C
To view and manage enrolled devices, assign policies, and perform remote actions such as wipe or restart
✓ Correct
-
D
To configure tenant settings and Azure AD integration
Explanation
The Devices section in Intune admin center provides visibility into enrolled devices and enables administrators to manage them through policy assignment, remote actions, and monitoring of compliance status.
You want to ensure that only devices with encryption enabled can access SharePoint Online. Which combination of technologies should be used?
-
A
Multi-factor authentication for all SharePoint users regardless of device state
-
B
Data loss prevention policy on SharePoint only
-
C
Application-based access control without device requirements
-
D
Device compliance policy with encryption requirement + Conditional Access policy requiring compliant devices
✓ Correct
Explanation
A device compliance policy that requires encryption, combined with a Conditional Access policy that blocks non-compliant devices, ensures only encrypted devices can access SharePoint Online.
An employee uses multiple devices (Windows PC, iPhone, and iPad) for work. What is the most efficient way to ensure all devices receive the same security policies?
-
A
Create separate policies for each device platform and assign to the user group
-
B
Assign policies to user groups instead of device groups
✓ Correct
-
C
Deploy a single universal policy that applies to all operating systems equally
-
D
Manually configure each device individually with identical settings
Explanation
Assigning policies to user groups ensures all devices owned by a user receive applicable policies automatically, regardless of platform. Intune then applies platform-specific policies as needed for each device type.
You are troubleshooting why a compliance policy is not applying to a Windows 10 device. What is the first diagnostic step you should take?
-
A
Disable and re-enable Intune enrollment from Settings
-
B
Check the device's compliance status in Intune and review the policy assignment to user/device groups
✓ Correct
-
C
Reinstall the Intune management agent immediately
-
D
Perform a factory reset of the device
Explanation
The first diagnostic step is verifying that the policy is correctly assigned to the user or device group and checking the device's reported compliance status. This identifies whether the policy is reaching the device or if there are assignment issues.
Which statement best describes the relationship between Azure AD and Intune in Microsoft endpoint management?
-
A
Azure AD and Intune are completely separate services with no integration or data sharing
-
B
Azure AD provides identity and access management, while Intune uses Azure AD for device identity and manages device policies and compliance
✓ Correct
-
C
Intune is a replacement for Azure AD and handles all identity and device management functions
-
D
Azure AD manages only user identities, while Intune manages only device hardware and firmware
Explanation
Azure AD serves as the identity backbone for Intune, providing user and device identities. Intune leverages this identity information to manage policies, compliance, and conditional access decisions.
You need to restrict personal app store installations on iOS devices while allowing access to managed apps. Which Intune policy type should be used?
-
A
Mobile Application Management (MAM) policy only
-
B
iOS device configuration profile with app restrictions
✓ Correct
-
C
Device compliance policy
-
D
Conditional Access policy for app-based controls
Explanation
An iOS device configuration profile allows granular control over app store access and installation permissions. It can restrict personal app store while allowing management of enrolled apps through Intune.
An organization has hybrid Azure AD-joined devices. What is the primary advantage of configuring co-management with Configuration Manager and Intune?
-
A
It eliminates the need for Azure AD enrollment entirely
-
B
It allows on-premises Group Policy to continue managing devices while gradually shifting workloads to Intune cloud management
✓ Correct
-
C
It provides local antivirus updates without cloud connectivity
-
D
It removes the requirement for on-premises Active Directory
Explanation
Co-management allows organizations to manage devices through both Configuration Manager and Intune simultaneously, enabling a gradual transition to cloud management while maintaining existing on-premises Group Policy controls.
A user reports that they cannot install a required company application from the Company Portal. What is the most likely reason if their device is compliant and they have the correct group assignment?
-
A
The device has insufficient storage space or the app requires an incompatible OS version
✓ Correct
-
B
The device must be factory reset before any apps can install
-
C
The user's Azure AD account is locked
-
D
Intune is not syncing with the app store
Explanation
Common installation failures occur when devices lack sufficient storage, have an OS version below the application's minimum requirement, or lack necessary prerequisites. Checking device compatibility and available storage should be the first troubleshooting step.
You are configuring a password policy for Windows 10 devices. The policy requires passwords to contain uppercase, lowercase, numbers, and symbols with a minimum length of 14 characters. After deployment, some devices report non-compliance. What could explain this?
-
A
Windows 10 devices only support a maximum password length of 10 characters
-
B
The devices may have cached credentials preventing policy update, or users have not yet met the requirement at next password change
✓ Correct
-
C
Password policies cannot be enforced on consumer editions of Windows 10
-
D
The Azure AD password hash is not synced with local device passwords
Explanation
Password policies typically apply at the next password change or credential refresh. Devices with cached credentials may show non-compliance until users update their passwords. This is expected behavior during policy rollout.
Which Windows 10 feature allows IT administrators to monitor and remotely manage devices without full enrollment in Intune?
-
A
Storage Spaces Direct
-
B
Windows Sandbox
-
C
Microsoft Defender for Endpoint
✓ Correct
-
D
Windows Update for Business
Explanation
Microsoft Defender for Endpoint (MDE) allows organizations to monitor devices for threats and manage security endpoints without requiring full Intune enrollment, though integration with Intune enhances capabilities.
An organization wants to deploy a custom configuration to only devices owned by the Finance department. What is the correct approach in Intune?
-
A
Deploy the profile to all devices and block non-Finance users from accessing it
-
B
Create a dynamic device group based on department attribute and assign the configuration profile to this group
✓ Correct
-
C
Create a static group, manually add Finance devices, and assign the profile
-
D
Manually configure each Finance department device individually
Explanation
Dynamic device groups automatically populate based on Azure AD attributes such as department. Assigning policies to these groups ensures scalability and automatic updates when devices move between departments.
You need to implement certificate-based authentication for VPN access on managed devices. What is the recommended configuration sequence in Intune?
-
A
Use self-signed certificates deployed through device configuration without a certificate profile
-
B
Require users to manually request certificates from the corporate PKI infrastructure
-
C
Configure the VPN profile first, then manually install certificates on each device
-
D
Deploy certificates first through a SCEP or PKCS profile, then reference the certificate in the VPN profile configuration
✓ Correct
Explanation
Intune allows automated deployment of SCEP or PKCS certificates to devices, which can then be referenced in VPN profiles. This ensures certificate-based authentication is configured consistently without manual intervention.
What does the 'Intune data warehouse' provide for endpoint administrators?
-
A
Direct access to modify device configurations from a data query interface
-
B
Historical reporting and analytics on device inventory, compliance trends, and policy effectiveness for business intelligence and decision-making
✓ Correct
-
C
Automatic remediation of non-compliant devices
-
D
Real-time alerting for all device compliance violations
Explanation
The Intune data warehouse collects and stores historical data, allowing administrators to create custom reports and analytics on device compliance, inventory, and policy effectiveness over time.
You need to configure Windows Update for Business settings in Intune to ensure devices receive updates on a specific schedule. Which setting controls the deferral period for quality updates?
-
A
Quality update deferral (days)
✓ Correct
-
B
Update expedite settings
-
C
Update ring
-
D
Automatic update behavior
Explanation
The 'Quality update deferral (days)' setting in Windows Update for Business allows you to specify how many days to defer quality updates after their release date.
Your organization requires conditional access policies to block access to Microsoft 365 from non-compliant devices. Which Azure AD conditional access component evaluates device compliance status?
-
A
Mark device as compliant action
-
B
Client apps condition
-
C
Device state condition
-
D
Require device to be marked as compliant control
✓ Correct
Explanation
The 'Require device to be marked as compliant' grant control in conditional access policies evaluates whether the device meets organizational compliance requirements before allowing access.
You are deploying Microsoft 365 Apps using Intune. Which deployment method allows you to target specific user groups with phased rollout capabilities?
-
A
Web app deployment
-
B
Win32 app deployment
-
C
Microsoft 365 Apps for enterprise deployment
✓ Correct
-
D
Line-of-business app deployment
Explanation
Microsoft 365 Apps for enterprise can be deployed through Intune with support for targeted group assignments and phased rollout configurations.
An organization needs to ensure that BitLocker recovery keys are securely stored and accessible for administrators. Where should BitLocker recovery keys be backed up in an Intune-managed environment?
-
A
Azure AD
✓ Correct
-
B
Local security database on each device
-
C
Active Directory Domain Services
-
D
Intune device configuration backup
Explanation
BitLocker recovery keys should be backed up to Azure AD (or Azure Information Protection) to ensure secure storage and administrator accessibility for Intune-managed devices.
You configure a device compliance policy in Intune that requires all Windows 10 devices to have Defender antimalware enabled. Which action occurs when a device fails to meet this requirement?
-
A
The device is marked as non-compliant and can trigger conditional access
✓ Correct
-
B
Defender is automatically enabled without user notification
-
C
A remediation script forces compliance within 24 hours
-
D
The device is immediately wiped
Explanation
When a device fails a compliance policy requirement, it is marked as non-compliant, which can then trigger conditional access policies to restrict access to company resources.
Your organization uses hybrid Azure AD joined devices. Which PowerShell module should you use to manage these devices in Intune?
-
A
Get-IntuneDeviceCompliancePolicy
-
B
Microsoft.Graph.Intune
✓ Correct
-
C
ActiveDirectory module
-
D
AzureAD module
Explanation
The Microsoft.Graph.Intune PowerShell module provides cmdlets to manage Intune resources including hybrid Azure AD joined devices through the Microsoft Graph API.
You need to deploy a custom line-of-business application to Windows devices using Intune. The application requires administrative privileges to install. Which app type should you use?
-
A
Web app
-
B
Microsoft Store app
-
C
Win32 app
✓ Correct
-
D
Built-in app
Explanation
Win32 apps in Intune support deployment of traditional Windows applications that require administrative privileges and can be packaged using the Intune Win32 Content Prep Tool.
Your organization implements a data loss prevention (DLP) policy that restricts copying data from Microsoft 365 apps to personal cloud storage. Which Intune feature enables this control?
-
A
App protection policy
✓ Correct
-
B
Compliance policy with conditional access
-
C
Device configuration profile
-
D
Mobile device management (MDM) enrollment
Explanation
Intune app protection policies allow you to implement DLP controls such as preventing data transfer to unmanaged apps and personal cloud storage accounts without requiring device enrollment.
You are configuring automatic enrollment for Windows 10 devices in Azure AD. Which prerequisite must be configured in Azure AD to enable MDM auto-enrollment?
-
A
MDM user scope setting and appropriate licenses
✓ Correct
-
B
Enterprise State Roaming
-
C
Passwordless sign-in configuration
-
D
Windows Hello for Business
Explanation
To enable automatic MDM enrollment, you must configure the MDM user scope setting in Azure AD and ensure users have appropriate Intune or Microsoft 365 licenses.
An organization needs to restrict which USB devices can connect to corporate Windows devices. Which Intune feature should you use to implement this control?
-
A
App protection policy restricting external media
-
B
Compliance policy checking USB device status
-
C
Device configuration profile with Device Control settings
✓ Correct
-
D
Endpoint security attack surface reduction rule
Explanation
Device Control settings within Intune device configuration profiles allow administrators to manage which USB and external storage devices can connect to Windows endpoints, enabling granular hardware access controls.