Automatic Intune Enrollment via MDM User Scope
You have a Microsoft 365 E5 subscription. You need to ensure that when a Windows device is joined to the Microsoft Entra tenant, the device is enrolled automatically in Microsoft Intune. What should you configure?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The core concept tested is the distinction between identity join settings and device management enrollment policies, with the common trap being confusion between Entra ID join options and Intune MDM scopes.
This question addresses the configuration required to automatically enroll Windows devices in Microsoft Intune upon joining a Microsoft Entra tenant. It establishes that configuring the MDM user scope is the correct mechanism for this automation.
Learners often select 'Microsoft Entra join and registration settings' because it handles identity, but it does not trigger the MDM enrollment process itself. They may also choose WIP or Enterprise State Roaming, which are unrelated to device management enrollment.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To ensure automatic enrollment of Windows devices in Microsoft Intune, you must configure the Mobile Device Management (MDM) user scope. This setting allows you to specify which users or groups are allowed to be managed by Intune and enables automatic enrollment for those entities when they interact with company resources.Why the Other Options Are Wrong
Microsoft Entra join and registration settings (Option C) handle the identity relationship between the user/device and the directory but do not initiate the MDM enrollment protocol. Windows Information Protection (Option A) is an app-protection feature, not an enrollment policy. Enterprise State Roaming (Option B) synchronizes settings across devices but does not enroll them into management.Community Comment Notes
The community consensus strongly supports Option D, with multiple comments confirming that the MDM user scope is the standard method for enabling automatic enrollment. As noted by user JayHall, this scope specifically enables automatic enrollment for Microsoft Intune device management.Official Reference
Exam Strategy
When configuring Intune enrollment, always distinguish between Identity (Entra ID Join) and Management (Intune MDM). Remember that 'Automatic Enrollment' is a specific capability found within the MDM User Scope settings, not the general join settings.
Frequently Asked Questions
Why doesn't Entra join automatically enroll devices?
Entra join only manages identity. MDM enrollment requires a separate policy like the MDM user scope to establish the management channel.
Can I use WIP for automatic enrollment?
No, Windows Information Protection is for data protection, not for enrolling devices into Intune management.
Related Analysis
Practice All MD-102 Questions
Access 92 questions with complete answers and detailed explanations.
View Full MD-102 Practice Test →