Pre-Summer Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

MD-102 Endpoint Administrator Questions and Answers

Questions 4

You have a Microsoft 365 subscription.

You plan to enroll devices in Microsoft Intune. You need to meet the following requirements:

• Only allow the enrollment of devices that have a specific international mobile equipment identifier (IMEI).

• Support the enrollment and management of up to 1,000 devices

Which enrollment setting should you configure for each requirement? To answer, drag the appropriate settings to the correct requirements. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

devices

Options:

Buy Now
Questions 5

You have a Microsoft 365 subscription that has Windows 365 Enterprise licenses.

You plan to use a custom Windows 11 image as a template for Cloud PCs.

You have a Hyper-V virtual machine that runs Windows 11 and has the following configurations:

• Name: VM1

• Disk size: 64 GB

• Disk format: VHDX

• Disk type: Fixed size

• Generation: Generation 2

You need to ensure that you can use VM1 as a source for the custom image. What should you do on VM1 first?

Options:

A.

Change the disk type to Dynamically expanding

B.

Change the disk format to the VHD

C.

Change the generation to Generation 1.

D.

Increase the disk size.

Buy Now
Questions 6

You have a Microsoft 365 subscription and use Microsoft Intune.

You have the Endpoint Privilege Management (EPM) elevation settings policy shown in the following exhibit.

No EPM elevation rules policies are configured.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 7

You have an Azure AD tenant and 100 Windows 10 devices that are Azure AD joined and managed by using Microsoft Intune.

You need to configure Microsoft Defender Firewall and Microsoft Defender Antivirus on the devices. The solution must minimize administrative effort.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

To configure Microsoft Defender Antivirus, create a Group Policy Object (GPO) and configure the Windows Defender Antivirus settings.

B.

To configure Microsoft Defender Firewall, create a device configuration profile and configure the Device restrictions settings.

C.

To configure Microsoft Defender Antivirus, create a device configuration profile and configure the Endpoint protection settings.

D.

To configure Microsoft Defender Antivirus, create a device configuration profile and configure the Device restrictions settings.

E.

To configure Microsoft Defender Firewall, create a device configuration profile and configure the Endpoint protection settings.

F.

To configure Microsoft Defender Firewall, create a Group Policy Object (GPO) and configure Windows Defender Firewall with Advanced Security.

Buy Now
Questions 8

You have a Microsoft 365 E5 tenant that contains Windows devices enrolled in Microsoft Intune as shown in the following table.

You create an Endpoint Privilege Management (EPM) elevation settings policy named ElevationSettmgsl that has the following settings:

• Endpoint Privilege Management: Enabled

o Default elevation response: Require user confirmation

o Validation: Business justification

• Assignments: Group1 Each device contains a file named File1.exe that can be run only by an administrator. You create an EPM elevation rules policy named ElevattonRules1 that has the following settings:

• Rule name: Rule1

o Elevation type: Automatic

o File name: Filel.exe

o File hash: < Filel.exe hash >

• Assignments: Group2

For each of the following statements, select Yes if the statement is true. Otherwise, select

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 9

You have a Microsoft Intune subscription.

You are creating a Windows Autopilot deployment profile named Profile1 as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 10

You have groups that use the Dynamic Device membership type as shown in the following table.

You are deploying Microsoft 365 apps.

You have devices enrolled in Microsoft Intune as shown in the following table.

In the Microsoft Endpoint Manager admin center, you create a Microsoft 365 Apps app as shown in the exhibit. (Click the Exhibit tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 11

You have a Microsoft Deployment Toolkit (MDT) deployment share named DS1.

in the Out-of-Box Drivers node, you create folders that contain drivers for different hardware models.

You need to configure the Inject Drivers MDT task to use PnP detection to install the drivers for one of the hardware models.

What should you do first?

Options:

A.

Import an OS package.

B.

Create a selection profile.

C.

Add a Gather task to the task sequence.

D.

Add a Validate task to the task sequence.

Buy Now
Questions 12

You have a Microsoft 365 subscription that contains 5,000 Windows devices enrolled in Microsoft Intune.

You plan to use the Sync and Collect diagnostics bulk device actions.

What is the maximum number of devices you can include in each action? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 13

You have a Microsoft 365 E5 subscription that includes Microsoft Intune.

You need to configure a compliance policy for the iOS/iPadOS platform. The solution must meet the following requirements:

• Require jailbroken devices to be marked as noncompliant.

• Mark devices without a password lock as noncompliant.

Which compliance policy settings should you configure for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 14

You have a Microsoft 365 E5 subscription.

You create a new update rings policy named Policy1 as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point,

Options:

Buy Now
Questions 15

You have devices enrolled in Microsoft Intune as shown in the following table.

Intune includes the device compliance policies shown in the following table.

The device compliance policies have the assignments shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 16

You have an Azure AD group named Group1. Group! contains two Windows 10 Enterprise devices named Device1 and Device2. You create a device configuration profile named Profile1. You assign Profile! to Group1. You need to ensure that Profile! applies to Device1 only. What should you modify in Profile 1?

Options:

A.

Assignments

B.

Settings

C.

Scope (Tags)

D.

Applicability Rules

Buy Now
Questions 17

In Microsoft Intune, you have the device compliance policies shown in the following table.

The Intune compliance policy settings are configured as shown in the following exhibit.

On June 1, you enroll Windows 11 devices in Intune as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point

Options:

Buy Now
Questions 18

You have a Microsoft 365 subscription that uses Microsoft Intune.

You need to ensure that you can deploy apps to Android Enterprise devices.

What should you do first?

Options:

A.

Create a configuration profile.

B.

Add a certificate connector.

C.

Configure the Partner device management settings.

D.

Link your managed Google Play account to Intune.

Buy Now
Questions 19

You have a Microsoft 365 subscription that includes Microsoft Intune.

You need to deploy a custom app to Android devices. The app uses the APK file format.

Which type of app should you select for the deployment?

Options:

A.

built-in

B.

Android store

C.

Managed Google Play

D.

line-of-business (LOB)

E.

web link

Buy Now
Questions 20

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory domain. The domain contains a computer named Computer1 that runs Windows 8.1.

Computer1 has apps that are compatible with Windows 10.

You need to perform a Windows 10 in-place upgrade on Computer1.

Solution: You copy the Windows 10 installation media to a Microsoft Deployment Toolkit (MDT) deployment share. You create a task sequence, and then you run the MDT deployment wizard on Computer1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 21

You have an Azure AD tenant that contains the devices shown in the following table.

You purchase Windows 11 Enterprise E5 licenses.

Which devices can use Subscription Activation to upgrade to Windows 11 Enterprise?

Options:

A.

Device1 only

B.

Device1 and Device2 only

C.

Device1 and Device3 only

D.

Device1, Device2, Device3, and Device4

Buy Now
Questions 22

You have devices enrolled in Microsoft Intune as shown in the following table.

On which devices can you apply app configuration policies?

Options:

A.

Device2 only

B.

Device1 and Device2 only

C.

Device3 and Device4 only

D.

Device2, Device3, and Device4 only

E.

Device1, Device2, Device B, and Device4

Buy Now
Questions 23

You have a Windows 10 device named Device! that is joined to Active Directory and enrolled in Microsoft Intune.

Device1 is managed by using Group Policy and Intune.

You need to ensure that the Intune settings override the Group Policy settings.

What should you configure?

Options:

A.

a device configuration profile

B.

a device compliance policy

C.

an MDM Security Baseline profile

D.

a Group Policy Object (GPO)

Buy Now
Questions 24

You have a Microsoft 365 E5 subscription and use Microsoft Intune.

You need to use a Sync bulk device action on all corporate-owned Windows devices.

What is the maximum number of devices you can include the action?

Options:

A.

25

B.

50

C.

100

D.

500

E.

1000

Buy Now
Questions 25

You are evaluating which devices are compliant.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 26

You have a Microsoft 365 E5 subscription and use Microsoft Intune Suite. You manage the following types of devices;

• Windows 11

• Android

• iOS

You need to implement Microsoft Tunnel for Mobile Application Management (MAM) to provide the devices with access to on-premises company apps.

What should you deploy first, and which device types can use Tunnel for MAM? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 27

You need to prepare for the deployment of the Phoenix office computers.

What should you do first?

Options:

A.

Extract the hardware ID information of each computer to a CSV file and upload the file from the Devices settings in Microsoft Store for Business.

B.

Generalize the computers and configure the Mobility (MDM and MAM) settings from the Azure ActiveDirectory blade in the Azure portal.

C.

Generalize the computers and configure the Device settings from the Azure Active Directory blade in the Azure portal.

D.

Extract the hardware ID information of each computer to an XLSX file and upload the file from the Devices settings in Microsoft Store for Business.

Buy Now
Questions 28

You need to meet the technical requirements for Windows AutoPilot.

Which two settings should you configure from the Azure Active Directory blade? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 29

You need to recommend a solution to meet the device management requirements.

What should you include in the recommendation? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 30

You need a new conditional access policy that has an assignment for Office 365 Exchange Online.

You need to configure the policy to meet the technical requirements for Group4.

Which two settings should you configure in the policy? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 31

What is the maximum number of devices that User1 and User2 can enroll in Intune? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 32

You need to meet the requirements for the MKG department users.

What should you do?

Options:

A.

Assign the MKG department users the Purchaser role in Microsoft Store for Business

B.

Download the APPX file for App1 from Microsoft Store for Business

C.

Add App1 to the private store

D.

Assign the MKG department users the Basic Purchaser role in Microsoft Store for Business

E.

Acquire App1 from Microsoft Store for Business

Buy Now
Questions 33

You need to prepare for the deployment of the Phoenix office computers.

What should you do first?

Options:

A.

Generalize the computers and configure the Mobility (MDM and MAM) settings from the Azure Active Directory admin center.

B.

Extract the hardware ID information of each computer to a CSV file and upload the file from the Microsoft Intune blade in the Azure portal.

C.

Extract the hardware ID information of each computer to an XML file and upload the file from the Devices settings in Microsoft Store for Business.

D.

Extract the serial number information of each computer to a CSV file and upload the file from the Microsoft Intune blade in the Azure portal.

Buy Now
Questions 34

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 35

Which user can enroll Device6 in Intune?

Options:

A.

User4 and User2 only

B.

User4 and User 1 only

C.

User1, User2, User3, and User4

D.

User4. User Land User2 only

Buy Now
Questions 36

You need to meet the technical requirements for the IT department.

What should you do first?

Options:

A.

From the Azure Active Directory blade in the Azure portal, enable Seamless single sign-on.

B.

From the Configuration Manager console, add an Intune subscription.

C.

From the Azure Active Directory blade in the Azure portal, configure the Mobility (MDM and MAM) settings.

D.

From the Microsoft Intune blade in the Azure portal, configure the Windows enrollment settings.

Buy Now
Questions 37

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 38

User1 and User2 plan to use Sync your settings.

On which devices can the users use Sync your settings? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 39

Which devices are registered by using the Windows Autopilot deployment service?

Options:

A.

Device1 only

B.

Device3 only

C.

Device1 and Device3 only

D.

Device1, Device2, and Device3

Buy Now
Questions 40

You need to ensure that computer objects can be created as part of the Windows Autopilot deployment. The solution must meet the technical requirements.

To what should you grant the right to create the computer objects?

Options:

A.

Server2

B.

Server1

C.

GroupA

D.

DC1

Buy Now
Questions 41

You need to resolve the performance issues in the Los Angeles office.

How should you configure the update settings? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 42

Which users can purchase and assign App1?

Options:

A.

User3 only

B.

User1 and User3 only

C.

User1, User2, User3, and User4

D.

User1, User3, and User4 only

E.

User3 and User4 only

Buy Now
Questions 43

What should you upgrade before you can configure the environment to support co-management?

Options:

A.

the domain functional level

B.

Configuration Manager

C.

the domain controllers

D.

Windows Server Update Services (WSUS)

Buy Now
Questions 44

You need to meet the device management requirements for the developers.

What should you implement?

Options:

A.

folder redirection

B.

Enterprise State Roaming

C.

home folders

D.

known folder redirection in Microsoft OneDrive

Buy Now
Questions 45

You implement the planned changes for Connection1 and Connection2

How many VPN connections will there be for User1 when the user signs in to Device 1 and Devke2? To answer select the appropriate options in the answer area.

NOTE; Each correct selection is worth one point.

Options:

Buy Now
Questions 46

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 47

What should you use to meet the technical requirements for Azure DevOps?

Options:

A.

An app protection policy

B.

Windows Information Protection (WIP)

C.

Conditional access

D.

A device configuration profile

Buy Now
Questions 48

You implement Boundary1 based on the planned changes.

Which devices have a network boundary of 192.168.1.0/24 applied?

Options:

A.

Device2 only

B.

Device3 only

C.

Device 1. Device2. and Device5 only

D.

Device 1, Device2, Device3, and Device4 only

Buy Now
Questions 49

You need to meet the technical requirements for the new HR department computers.

How should you configure the provisioning package? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 50

You need to meet the OOBE requirements for Windows AutoPilot.

Which two settings should you configure from the Azure Active Directory blade? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 51

You need to capture the required information for the sales department computers to meet the technical

requirements.

Which Windows PowerShell command should you run first?

Options:

A.

Install-Module WindowsAutoPilotIntune

B.

Install-Script Get-WindowsAutoPilotInfo

C.

Import-AutoPilotCSV

D.

Get-WindowsAutoPilotInfo

Buy Now
Questions 52

What should you configure to meet the technical requirements for the Azure AD-joined computers?

Options:

A.

Windows Hello for Business from the Microsoft Intune blade in the Azure portal.

B.

The Accounts options in an endpoint protection profile.

C.

The Password Policy settings in a Group Policy object (GPO).

D.

A password policy from the Microsoft Office 365 portal.

Buy Now
Questions 53

You have computers that run Windows 10 and are managed by using Microsoft Intune.

Users store their files in a folder named D:\Folder1.

You need to ensure that only a trusted list of applications is granted write access to D:\Folder1.

What should you configure in the device configuration profile?

Options:

A.

Microsoft Defender Exploit Guard

B.

Microsoft Defender Application Guard

C.

Microsoft Defender SmartScreen

D.

Microsoft Defender Application Control

Buy Now
Questions 54

You have a Microsoft 365 subscription that contains the following devices enrolled in Microsoft Intune:

• A corporate-owned Windows device named Device1

• A personally-owned Android device named Device2

You need to use a remote action on each device.

The solution must meet the following requirements:

• Repurpose Device1 by returning the device to the factory default settings.

• Remove only corporate data from Device2 and remove the device from Intune when the device checks in.

Which remote action should you use on each device? To answer, drag the appropriate remote actions to the correct devices. Each remote action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Exam Code: MD-102
Exam Name: Endpoint Administrator
Last Update: May 14, 2026
Questions: 363
MD-102 pdf

MD-102 PDF

$28.5  $94.99
MD-102 Engine

MD-102 Testing Engine

$33  $109.99
MD-102 PDF + Engine

MD-102 PDF + Testing Engine

$43.5  $144.99