Big Halloween Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Microsoft MD-102 Practice Exam with Questions & Answers | Set: 5

Questions 41

You have a Microsoft 365 E5 subscription and use Microsoft Intune Suite. You manage the following types of devices;

• Windows 11

• Android

• iOS

You need to implement Microsoft Tunnel for Mobile Application Management (MAM) to provide the devices with access to on-premises company apps.

What should you deploy first, and which device types can use Tunnel for MAM? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

MD-102 Question 41

Options:
Microsoft MD-102 Premium Access
Questions 42

You have a Microsoft Intune subscription.

You have devices enrolled in intune as shown in the following table.

MD-102 Question 42

An app named App1 is installed on each device.

What is the minimum number of app configuration policies required to manage Appl ?

Options:
A.

1

B.

2

C.

3

D.

4

E.

5

Questions 43

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Microsoft Intune to manage devices.

You use Windows Autopilot to deploy Windows 11 to devices.

A support engineer reports that when a deployment fails, they cannot collect deployment logs from failed device.

You need to ensure that when a deployment fails, the deployment logs can be collected.

What should you configure?

Options:
A.

the automatic enrollment settings

B.

the Windows Autopilot deployment profile

C.

the enrollment status page (ESP) profile

D.

the device configuration profile

Questions 44

Your network contains an on-premises Active Directory Domain Services {AD DS) domain that syncs with an Azure AD tenant by using Azure AD Connect.

You use Microsoft Intune and Configuration Manager to manage devices.

You need to recommend a deployment plan for new Windows 11 devices. The solution must meet the following requirements:

• Devices for the marketing department must be joined to the AD DS domain only. The IT department will install complex applications on the devices at build time, before giving the devices to the marketing department users.

• Devices for The sales department must be Azure AD joined. The devices will be shipped directly from the manufacturer to The homes of the sales department users.

• Administrative effort must be minimized.

Which deployment method should you recommend for each department? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

MD-102 Question 44

Options:
Questions 45

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Microsoft Intune to manage Windows 11 devices.

You create a new policy set named Set and add five device configuration profiles for Windows 10 and later.

You create a device compliance policy named Policy1.

You need to ensure that when users are assigned the device configuration profiles in Set1, they are always assigned Policy1 also.

What should you configure?

Options:
A.

the assignments of Policy1

B.

the Policy1 configurations

C.

the assignments of Set1

D.

the Set1 configurations

Questions 46

You have 200 computers that run Windows 10. The computers are joined to Microsoft Entra and enrolled in Microsoft Intune. You need to enable self-service password reset on the sign-in screen. Which settings should you configure from the Microsoft Intune admin center?

Options:
A.

Conditional access

B.

Device compliance

C.

Device configuration

D.

Device enrollment

Questions 47

You have a Microsoft 365 E5 subscription and use Microsoft Intune.

You need to use a Sync bulk device action on all corporate-owned Windows devices.

What is the maximum number of devices you can include the action?

Options:
A.

25

B.

50

C.

100

D.

500

E.

1000

Questions 48

Your network contains an Active Directory domain. The domain contains 2,000 computers that run Windows 10. You implement hybrid Azure AD and Microsoft Intune.

You need to automatically register all the existing computers to Azure AD and enroll the computers in Intune. The solution must minimize administrative effort.

What should you use?

Options:
A.

an Autodiscover address record

B.

a Group Policy object (GPO)

C.

an Autodiscover service connection point (SCP)

D.

a Windows Autopilot deployment profile

Questions 49

You have a Microsoft 365 E5 subscription.

All devices are enrolled in Microsoft Intune.

You need to ensure that devices that have NOT checked in for 30 days are deleted from intune.

What should you configure from the Microsoft Intune admin center?

Options:
A.

a device limit restriction

B.

automatic enrollment

C.

a device clean-up rule

D.

a configuration profile

Questions 50

You have a Microsoft 365 E5 subscription that contains the groups shown in the following table.

MD-102 Question 50

You create a Conditional Access policy named CAPolicy1 that will block access to Microsoft Exchange Online from iOS devices. You assign CAPolicy1 to Group1.

You discover that User1 can still connect to Exchange Online from an iOS device.

You need to ensure that CAPolicy1 is enforced.

What should you do?

Options:
A.

Configure a new terms of use (TOU).

B.

Assign CAPolicy1 to Group2.

C.

Enable CAPolicy1

D.

Add a condition in CAPolicy1 to filter for devices.

Exam Code: MD-102
Certification Provider: Microsoft
Exam Name: Endpoint Administrator
Last Update: Oct 30, 2025
Questions: 346