What Must Be Done First to Use Intune Device Query?
You have a Microsoft 365 E5 subscription. You need to use Device query to gather information about all the devices that are managed by using Microsoft Intune. What should you do first?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the prerequisite chain for Intune Device query — Endpoint analytics onboarding (plus Advanced Analytics licensing) — and the trap is reaching for Defender for Endpoint or Endpoint analytics configuration as if they were the enabling step.
Microsoft Intune Device query only returns results for devices that are onboarded to Endpoint analytics, and it additionally relies on the Advanced Analytics licensing included in the Intune Suite or the Advanced Analytics add-on. This page confirms that onboarding devices to Endpoint analytics is the required first step, not Defender for Endpoint onboarding or a compliance policy.
Choosing to onboard the devices to Microsoft Defender for Endpoint, because Device query lives next to advanced hunting and live response in the security tooling family; Defender onboarding feeds Defender-specific telemetry, not the Endpoint analytics dataset that Device query reads.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Device query is a Microsoft Intune feature that runs KQL-style queries against the inventory and telemetry data collected by Endpoint analytics, so a device can only be queried once it has been enrolled/onboarded to Endpoint analytics and has begun reporting. Availability also depends on licensing that includes Microsoft Intune Advanced Analytics, delivered through the Intune Advanced Analytics Add-on or the Microsoft Intune Suite — the E5 subscription in the scenario does not by itself satisfy that prerequisite, but the practical "first" step asked about is the onboarding. As Moot2 noted, "To use Device query on a device, the device must be enrolled in Endpoint Analytics", which matches Microsoft's documented requirement. Onboarding to Endpoint analytics therefore delivers the data source that Device query consumes, making option C the enabling action.Why the Other Options Are Wrong
Enabling Windows license verification (A) is a Defender for Endpoint/Windows licensing check with no bearing on whether Device query can see a device. Onboarding devices to Microsoft Defender for Endpoint (B) populates Defender XDR data — a different dataset, useful for advanced hunting but not the Endpoint analytics reports and Device query schema. Creating a compliance policy for all devices (D) merely sets a state rule and produces compliance status; it neither onboards devices to Endpoint analytics nor creates the telemetry store Device query reads. None of A, B or D removes the actual blocker, which is that the device must be reporting into Endpoint analytics.Community Comment Notes
The voting on this item is unanimous at C, and the reasoning in the comments is the licensing and onboarding chain rather than guesswork. Moot2 supplied the vendor link to the Device query documentation and quoted its requirement that a device "must be enrolled in Endpoint Analytics". JayHall added a licensing nuance — Advanced Analytics ships with the Intune Advanced Analytics Add-on or Microsoft Intune Suite — which is a useful reminder that in a real tenant you must also confirm the entitlement, not just the onboarding. AleFCI1908 simply confirmed the answer. The consensus lines up with the vendor documentation, so C is safe to rely on for MD-102.Official Reference
Exam Strategy
Memorise the prerequisite chain for each analytics feature, not just their names: Endpoint analytics onboarding + Advanced Analytics licensing = Device query. When a question asks what to do "first", pick the action that creates the data source the feature reads, not a policy or a security-tool onboarding that merely sits adjacent to it.
Frequently Asked Questions
Do devices really need Endpoint analytics onboarding before Device query works?
Yes. Device query reads the dataset collected by Endpoint analytics, so an unonboarded device has no data to query and will not appear in results.
Isn't onboarding to Defender for Endpoint enough to run Device query?
No. Defender for Endpoint onboarding feeds Defender XDR telemetry for advanced hunting; Device query in Intune depends on Endpoint analytics data and Advanced Analytics licensing.
Related Analysis
Practice All MD-102 Questions
Access 92 questions with complete answers and detailed explanations.
View Full MD-102 Practice Test →