MD-102 — Frequently Asked Questions
Community-vetted answers to 78 common questions about this exam.
Questions from real practice questions
Each Q&A comes from a specific community question — follow the link for its full analysis.
Managing Updates with Microsoft Intune
Yes, Intune allows you to configure policies to automatically install iOS and iPadOS updates on managed devices.
Yes, Intune supports managing system updates for Android devices through device restriction policies and update rings.
SCEP Root Certificate Location for Intune
Clients must trust the Root CA to validate the chain. Server 2 is a subordinate CA signed by the Root CA (Server 3); trusting only Server 2 would break validation if the Root CA changes.
NDES (Network Device Enrollment Service) allows non-Windows or simple devices to request certificates. It pulls requests from clients and forwards them to the Subordinate CA for issuance.
Intune App Deployment Supported Platforms
Intune supports enrollment and compliance for Linux devices, but it does NOT support app deployment to Linux devices.
Android is one of the four primary platforms supported by Intune for full app management and deployment alongside Windows, iOS, and macOS.
How to Implement Windows LAPS in Microsoft Intune
Although LAPS settings can be reached through the settings catalog, Intune's dedicated Windows LAPS policy is created under Endpoint security > Account protection, which is what MD-102 expects.
Windows LAPS backs up the password to Microsoft Entra ID or to Windows Server Active Directory, so the tenant needs one of those directory services available.
Which Two Update Types Does Intune macOS Policy1 Install?
Critical updates are a separate category in the Intune macOS update policy; 'All other updates (OS, built-in apps)' excludes them.
No. Firmware is its own update category in macOS software update policies and requires separate configuration.
Assigning Intune and Cloud PC Roles with Least Privilege
It manages Cloud PC provisioning but lacks permissions to create or assign Intune applications and policies.
No, it grants only the specific combined permissions needed, avoiding the excess access found in broader built-in roles like Global Administrator.
Where Do You Set the Android Enterprise Maintenance Window in Intune?
The System update maintenance window in Android Enterprise device restrictions lives under General, not Device experience, so choosing Device experience will not expose the maintenance window fields.
In Profile1, open General > System update, select Maintenance window, then set the maintenance window start and end times.
What Can Intune App Protection Policy Protect on Windows Devices?
Intune app protection policies on Windows only support Microsoft Edge. Outlook MAM policies apply to iOS and Android devices, not Windows.
Yes, but on Windows the only supported app for app protection policies is Microsoft Edge; device configuration profiles handle other settings.
How Do You Scope a Conditional Access Policy to Only Noncompliant Devices?
Grant controls state what a user must satisfy to gain access; they do not limit which devices the policy evaluates. Setting that Grant control blocks or challenges noncompliant devices instead of scoping the policy to them.
Use the IsCompliant property with the operator Equals and the value No (or NotEquals/Yes), configured under Conditions > Filter for devices in the Conditional Access policy.
How to Deploy Remote Help to All Intune Devices?
Although Remote Help appears in the Microsoft Store, Intune's documented deployment for this exam scenario uses the Win32 app package; Store deployment is a minority community suggestion.
Yes — you can update by superseding the Win32 app in Intune, which keeps all enrolled devices current with minimal ongoing administrative effort.
How Many Intune Profiles Are Needed for Cloud PKI User Certificates?
Cloud PKI is provisioned under Tenant administration and creates the root and issuing CAs as a service, not as a device configuration profile, so it adds nothing to the profile count.
The SCEP certificate profile references the trusted certificate profile and returns the issuing CA in the issued chain, so a separate trusted profile for the issuing CA is not part of the minimum deployment.
What Must Be Purchased First for Intune Device Query at Minimum Cost?
Onboarding is a device-level prerequisite, but Device query also requires a tenant license that includes Intune Advanced Analytics, which Microsoft 365 E5 does not provide.
The Intune Suite includes Advanced Analytics but bundles many extra products and costs more; the question requires minimizing costs, so the standalone Advanced Analytics add-on is cheaper.
Does Microsoft Authenticator Register an Android Device in Entra ID?
Yes. Microsoft's device registration documentation lists the Authenticator app for iOS/Android, so adding a work or school account creates an Entra registered device object.
Company Portal is another valid method, not the only one. The question only asks whether the Authenticator solution meets the registration goal, and it does.
Can Helpdesk Administrator rotate BitLocker recovery keys in Intune?
It is a Microsoft Entra directory role, while Intune key rotation requires an Intune RBAC role with the Remote tasks Rotate BitLockerKeys permission, such as Helpdesk Operator.
Built-in Intune roles such as Helpdesk Operator include the Rotate BitLockerKeys right, or you can use a custom Intune RBAC role with that Remote tasks permission enabled.
Can Endpoint Security Manager Rotate BitLocker Recovery Keys in Intune?
They assume only Help Desk Operator holds the Rotate BitLockerKeys right, but Microsoft Learn lists Endpoint Security Manager with the same Rotate BitLockerKeys (preview) remote task.
No. Intune's built-in security role is named Endpoint Security Manager; 'Endpoint Security Administrator' is not one of the Intune RBAC built-in roles.
Intune device manufacturer restrictions: which device types support them?
Microsoft documents the manufacturer setting only for Android device platform restrictions; Windows and iOS exposure settings cover OS version and ownership instead.
No. Windows device platform restrictions do not include a manufacturer list; use separate Windows Autopilot deployment profile filters if you need model or manufacturer targeting.
Prevent Data Copy Paste Between Excel and Other Apps
App Configuration Policies only set app-specific settings (like URLs) and cannot enforce security controls like blocking clipboard access between apps.
Yes, App Protection Policies also apply to Android devices, allowing similar DLP controls like restricting copy/paste to managed apps.
Intune Update Ring for Phased Security Updates
Device configuration profiles apply settings like certificates or Wi-Fi, but they cannot schedule or phase the deployment of Windows updates.
No, you need separate update rings assigned to different device groups to apply different delay timelines for QA versus production.
Preventing Users from Disabling Microsoft Defender for Endpoint
No, Tamper Protection is enabled centrally in the Microsoft 365 Defender portal. Intune does not have a native setting to toggle this specific feature.
It configures Windows Hello for Business, FIDO2 security keys, and Credential Guard, but it does not control antivirus disablement permissions.
Customizing Windows 365 Cloud PC Image Source
Windows 365 provisioning infrastructure currently requires the legacy VHD format for custom images to ensure broad compatibility during the upload and conversion process.
Yes, you can use a Generation 2 VM, but you must still convert its disk from VHDX to VHD format before uploading it as a custom image.
Which Intune-Enrolled Devices Support Device Query?
Device query is limited to devices running Windows 10 or later. Device2 runs an operating system that does not meet this requirement, so it is not supported.
Yes, as long as the device runs Windows 10 or later and is enrolled in Intune, Device query can be used. The table shows Device1 as the only such device.
What Must Be Done First to Use Intune Device Query?
Yes. Device query reads the dataset collected by Endpoint analytics, so an unonboarded device has no data to query and will not appear in results.
No. Defender for Endpoint onboarding feeds Defender XDR telemetry for advanced hunting; Device query in Intune depends on Endpoint analytics data and Advanced Analytics licensing.
First step for Android Enterprise zero-touch enrollment in Intune?
The zero-touch portal can claim devices for an organization, but Intune must first be connected to Managed Google Play so the claimed devices have an Android Enterprise enrollment target.
No. Enrollment restrictions control enrollment eligibility and are not the prerequisite for enabling Android Enterprise zero-touch; link the Managed Google Play account first.
How Is a Help Desk Group Added to Local Administrators on Entra Joined Devices?
Cloud Device Administrator only manages device objects in Entra ID (enable, disable, delete, read BitLocker keys). It grants no rights on the Windows client, so members never enter the local Administrators group.
No. LAPS backs up and rotates the password of a designated local administrator account; it does not add users or groups to the local Administrators group on joined devices.
Intune Device Query Supported Devices
Device Query requires devices to be Microsoft Entra Joined. Registered devices do not have the same level of identity integration and telemetry access required for this feature.
No, Device Query is currently only supported on Windows 10 and later devices.
Endpoint Privilege Management Device Eligibility
EPM requires full management capabilities provided by Entra Joined or Hybrid Joined states. Registered devices lack the necessary policy enforcement and identity context for privilege escalation controls.
No, EPM is exclusively designed for Windows 10 and Windows 11 devices running on x64 or ARM64 architectures.
Restrict Device Join to Specific Group in Microsoft Entra ID
It is found in the Microsoft Entra admin center under Identity > Devices > Device settings.
No, User settings manage personalization and roaming; Device settings control join permissions.
Capabilities of a User-Registered Device in Microsoft Entra ID
Yes, Conditional Access policies can evaluate device state (registered vs. compliant), but the device itself cannot enforce policies like encryption.
Registration links the device to Entra ID for SSO; Enrollment adds the device to Intune for management and policy enforcement.
Dynamic Device Group Rule for Marketing Name
The -contains operator natively supports substring matching, so wildcards are redundant and cause syntax errors.
-contains checks if a value is a substring of another, while -in checks if the value exists in a predefined list of exact strings.
Automatic Intune Enrollment via MDM User Scope
Entra join only manages identity. MDM enrollment requires a separate policy like the MDM user scope to establish the management channel.
No, Windows Information Protection is for data protection, not for enrolling devices into Intune management.
Register Android Device in Entra ID via Company Portal
While technical provisioning exists, Company Portal is the standard user-facing method for self-service registration and enrollment in BYOD scenarios.
Company Portal performs both actions: it first registers the device with Entra ID for identity, then enrolls it in Intune for management.
Registering Android Device in Microsoft Entra ID
Entra Connect syncs users/groups from on-prem AD to cloud, it does not manage or register endpoint devices.
Use the Microsoft Authenticator app, Settings app, or enroll via Intune Company Portal depending on the scenario.
Help Desk Operator Role BitLocker Rotation
Yes, the Help Desk Operator role includes permissions to rotate both BitLocker (Windows) and FileVault (macOS) recovery keys.
It may be marked as preview in some contexts, but the Help Desk Operator role is designed to support this remote action.
Entra Registered vs Joined for Personal Device SSO
Entra joined requires full device management and often MDM enrollment, which violates the requirement to minimize organizational control on personal devices.
It allows users to sign in to Microsoft 365 services using their work credentials (SSO) without the organization having to manage or secure the device itself.
Microsoft Entra Joined vs Hybrid Join for MD-102
Yes, they can use Azure AD SSO or Kerberos delegation to access shares without credential prompts.
Hybrid Join increases on-premises reliance by syncing device objects to AD DS, contradicting the requirement.
Intune Remote Wipe Resume on Power Off
No, Autopilot Reset generally requires the device to be online and enrolled to initiate the process. It does not queue like Wipe.
Retire removes management but keeps user data. Wipe performs a full factory reset, removing all data and settings.
Intune Enrollment Notification Types for New Devices
No, Intune does not support SMS as a channel for enrollment notifications. Only email and push notifications are available.
While Teams is integrated into Microsoft 365, Intune's native enrollment notification feature does not include Teams messaging as a delivery method.
Intune Remediation Script Prerequisites
Remediations require an Intune Suite license. The verification toggle confirms your tenant has this entitlement before allowing script execution.
No. Even with E5, you must explicitly toggle the verification setting in the admin center to activate the feature for script management.
Enroll Android Enterprise Corporate-Owned Fully Managed Devices
Company Portal is designed for user-initiated enrollment of personal devices. Corporate-owned fully managed devices are typically enrolled via QR codes or Zero Touch for automated, policy-driven setup.
It indicates the device is owned by the organization and has full management capabilities, allowing for complete control over apps, settings, and security policies without user interference.
Ready to practice?
Access 92 MD-102 questions with instant feedback and detailed explanations.
View MD-102 Practice Questions →