First step for Android Enterprise zero-touch enrollment in Intune?

Enroll devices to Microsoft Intune
Answer Correct answer: C — Link a Managed Google Play account from the Microsoft Intune admin center before configuring zero-touch enrollment.

You have a Microsoft 365 E5 subscription. You need to enroll Android Enterprise devices in Microsoft Intune by using zero-touch enrollment. What should you do first?

  1. From the Microsoft Intune admin center, configure enrollment restrictions.
  2. From the Microsoft Intune admin center, create a zero-touch configuration.
  3. From the Microsoft Intune admin center, link a Managed Google Play account. Correct Answer
  4. From the zero-touch enrollment portal, create a zero-touch configuration.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This item tests the prerequisite order for Android Enterprise zero-touch enrollment, and the trap is choosing to create a zero-touch configuration in Intune or the Google portal before linking Managed Google Play.

Android Enterprise zero-touch enrollment in Microsoft Intune requires a tenant-level connection to Managed Google Play, so this MD-102 question establishes that linking a Managed Google Play account (C) must be done before creating any zero-touch configuration.

The most common wrong pick is D—creating a zero-touch configuration from the zero-touch enrollment portal—because learners associate zero-touch with Google’s portal, but Intune cannot enroll those devices until Managed Google Play is linked.

Community Discussion (3 comments)

Moot2 👍 2 Selected: C
C https://learn.microsoft.com/en-us/mem/intune/enrollment/android-dedicated-devices-fully-managed-enroll#enroll-by-using-google-zero-touch
AleFCI1908 👍 1 Selected: C
yes, first step is link the gplay acocunt
JayHall 👍 2
Answer is correct: From the Microsoft Intune admin center, link a Managed Google Play account. The first step to configure Android enterprise in your environment is to connect your Intune tenant account to your Android enterprise account: 1. Create a Google service account (@gmail.com). 2. Sign in to the Microsoft Intune admin center by using your Intune-licensed Global Administrator account. 3. Go to Devices > Android > Android Enrollment > Managed Google Play, select I agree, and then select Launch Google to connect now to open the Managed Google Play website. 4. Sign in to your Google account, and then select Get started. 5. Enter your business name, and then select Next. 6. Accept the terms, and then select Confirm. 7. Select Complete Registration. https://learn.microsoft.com/en-us/troubleshoot/mem/intune/device-enrollment/configure-android-enterprise-devices-intune

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Zero-touch enrollment for Android Enterprise depends on Intune being connected to Managed Google Play; without that linkage, Intune has no Android Enterprise enrollment channel to bind the zero-touch devices to. Linking a Managed Google Play account (C) establishes the tenant-level Android Enterprise connection, so it must happen before you create any Intune enrollment profile or zero-touch configuration. The zero-touch portal can only associate devices with an organization after the enterprise is connected, so link the account first. This matches Microsoft's documented prerequisite order for corporate-owned dedicated and fully managed zero-touch enrollment.

Why the Other Options Are Wrong

A is wrong because enrollment restrictions control who or what can enroll, not whether Android Enterprise zero-touch is enabled; restrictions are configured after the Android Enterprise connection exists. B is tempting, but an Intune zero-touch configuration cannot be applied until the Managed Google Play account is linked, so it is not the first step. D reverses the dependency: the zero-touch enrollment portal is where a reseller or organization handles device claims, but it does not replace the Intune–Managed Google Play tenant connection that zero-touch enrollment requires. Creating a zero-touch configuration in the Google portal before linking the account would leave Intune unable to manage the enrollment.

Community Comment Notes

JayHall outlined the exact prerequisite sequence, including creating a Google service account and signing in to the Intune admin center with an Intune-licensed Global Administrator before connecting Android enterprise. AleFCI1908 agreed that the "first step is link the gplay acocunt," reinforcing the account-linkage prerequisite. Moot2 linked Microsoft's documented zero-touch enrollment procedure, which supports treating the Managed Google Play connection as the initial required action. The unanimous C votes reflect the same ordering principle rather than an arbitrary majority.

Official Reference

Exam Strategy

When an MD-102 question asks for the first step, look for the tenant-level service connection needed before device-level or reseller-level configuration. For Android Enterprise, that connection is always the Managed Google Play account link, so choose it before enrollment profiles, restrictions, or zero-touch portal settings.

Frequently Asked Questions

Why isn't a zero-touch configuration created in the zero-touch portal the first step?

The zero-touch portal can claim devices for an organization, but Intune must first be connected to Managed Google Play so the claimed devices have an Android Enterprise enrollment target.

Do enrollment restrictions need to be configured before linking Managed Google Play?

No. Enrollment restrictions control enrollment eligibility and are not the prerequisite for enabling Android Enterprise zero-touch; link the Managed Google Play account first.

Related Analysis

Practice All MD-102 Questions

Access 92 questions with complete answers and detailed explanations.

View Full MD-102 Practice Test →

← Back to MD-102 Study Guide