Endpoint Privilege Management Device Eligibility

Configure endpoint security
Answer Correct answer: A — Only Device1 meets all Endpoint Privilege Management prerequisites: Windows 10/11 OS, Microsoft Entra Joined status, and Intune enrollment.

You have a Microsoft Entra tenant that contains the devices shown in the following table. On which devices can you implement Endpoint Privilege Management (EPM)? - image

  1. Device1 only Correct Answer
  2. Device1 and Device2 only
  3. Device1 and Device3 only
  4. Device1, Device3, and Device4 only
  5. Device1, Device2, Device3, and Device4

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests EPM prerequisites: Windows OS, Entra Joined/Hybrid Joined status, and Intune Enrollment. The trap is assuming Android or Entra Registered devices are eligible.

Determines which devices support Endpoint Privilege Management (EPM) based on OS, Entra ID join status, and Intune enrollment. The correct answer identifies that only Windows 10/11 devices joined to Entra ID and enrolled in Intune qualify.

Many learners select options including Device2 or Device3 because they overlook the specific requirement for 'Entra Joined' vs 'Entra Registered' or fail to check Intune enrollment status.

Community Discussion (6 comments)

Knight_Of_Peace 👍 2 Selected: A
Device must be Entra ID joined and Intune Enrolled. "Requirements Endpoint Privilege Management has the following requirements: - Microsoft Entra joined or Microsoft Entra hybrid joined. - Microsoft Intune Enrollment or Microsoft Configuration Manager co-managed devices (no workload requirements). - Supported Operating System. - Clear line of sight (without SSL-Inspection) to the required endpoints. Note: - Windows 365 (CloudPC) is supported using a supported operating system version - Workplace-join devices are not supported by Endpoint Privilege Management - Azure Virtual Desktop is not supported by Endpoint Privilege Management" Ref: https://learn.microsoft.com/en-us/mem/intune/protect/epm-overview#prerequisites:~:text=on%20capabilities.-,Requirements,Azure%20Virtual%20Desktop%20is%20not%20supported%20by%20Endpoint%20Privilege%20Management,-Endpoint%20Privilege%20Management
Meek_Learner 👍 2 Selected: A
Endpoint Privilege Management (EPM) has the following requirements: 1. Device must be running Windows 10 or Windows 11 – Device1, Device2, and Device3 qualify. Device4 (Android) is not supported. 2. Device must be Microsoft Entra Joined or Microsoft Entra Hybrid Joined – Device1 and Device2 qualify. Device3 and Device4 are only Microsoft Entra Registered, which is not supported. 3. Device must be enrolled in Microsoft Intune – Device1 and Device3 qualify. Device2 is not enrolled in Intune, making it ineligible. Thus, only Device1 meets all requirements for EPM implementation.
diazed 👍 1 Selected: A
Given answer is correct Applies to: Windows 10 /Windows 11 Endpoint Privilege Management has the following requirements: Microsoft Entra joined or Microsoft Entra hybrid joined Microsoft Intune Enrollment or Microsoft Configuration Manager co-managed devices (no workload requirements) Supported Operating System Clear line of sight (without SSL-Inspection) to the required endpoints https://learn.microsoft.com/en-us/mem/intune/protect/epm-overview
DiligentSam 👍 4
Given answer is correct Applies to: Windows 10 /Windows 11 Endpoint Privilege Management has the following requirements: Microsoft Entra joined or Microsoft Entra hybrid joined Microsoft Intune Enrollment or Microsoft Configuration Manager co-managed devices (no workload requirements) Supported Operating System Clear line of sight (without SSL-Inspection) to the required endpoints https://learn.microsoft.com/en-us/mem/intune/protect/epm-overview
martinods 👍 3
A: Correct Requirements Endpoint Privilege Management has the following requirements: Microsoft Entra joined or Microsoft Entra hybrid joined Microsoft Intune Enrollment or Microsoft Configuration Manager co-managed devices (no workload requirements) Supported Operating System Clear line of sight (without SSL-Inspection) to the required endpoints
Crille 👍 1
Correct answer C https://learn.microsoft.com/en-us/mem/intune/protect/epm-overview#prerequisites

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Endpoint Privilege Management (EPM) requires devices to run Windows 10 or Windows 11, be Microsoft Entra joined or Microsoft Entra hybrid joined, and be managed by Microsoft Intune or Configuration Manager. Based on typical exam table structures for this question:
  • Device1: Windows 10, Entra Joined, Intune Enrolled -> Eligible.
  • Device2: Often Windows 10 but may lack Intune enrollment or have a different join type (e.g., Azure AD Registered) in some variations, but usually, if it's Windows and Intune enrolled, it might be eligible. However, looking at the community consensus pointing to A, let's re-evaluate.
Actually, let's look at Comment 6 which says "Correct answer C" and links to Microsoft docs. Comment 4 says "Device1, Device2, and Device3 qualify" for OS, but Device3 is Entra Registered. Comment 6 implies C is correct. Let's look closer at the constraints. Microsoft Docs state: "Endpoint Privilege Management has the following requirements:... Microsoft Entra joined or Microsoft Entra hybrid joined... Supported Operating System... Clear line of sight..." If Device1 is Win10 + Entra Joined + Intune Enrolled, it works. If Device2 is Win10 + Entra Hybrid Joined + Intune Enrolled, it works. If Device3 is Win10 + Entra Registered, it does NOT work (must be Joined or Hybrid Joined). If Device4 is Android, it does NOT work. So why would A be the suggested answer? Perhaps Device2 is NOT Intune Enrolled? Or perhaps Device2 is Entra Registered? Let's look at Comment 6 again: "Correct answer C". This suggests Device1 and Device3 are eligible. But Device3 is Entra Registered in Comment 4's description. Wait, Comment 4 describes the devices. If Comment 6 is right, then my assumption about Device3 being Registered might be wrong for THIS specific image, OR the requirement allows Registered? No, docs say Joined/Hybrid. Let's re-read Comment 1: "Given answer is correct... Applies to: Windows 10 /Windows 11... Microsoft Entra joined or Microsoft Entra hybrid joined... Microsoft Intune Enrollment..." If the Suggested Answer is A, and Votes are 100% A, there is strong community pressure for A. However, Comment 6 explicitly cites Microsoft docs and says C. This is a conflict. Let's assume the table in the image (which I can't see but must infer from comments): Common MD-102 question pattern: Device 1: Win 10, Entra Joined, Intune Enrolled. Device 2: Win 10, Entra Joined, NOT Intune Enrolled (or CMG only?). Device 3: Win 10, Entra Registered, Intune Enrolled. Device 4: Android. If EPM requires Intune Enrollment AND Entra Join, then only Device 1 qualifies. This makes A correct. Comment 4 argues Device 2 qualifies for OS, Device 3 is Registered (not Joined). So 3 is out. Does 2 qualify? If 2 is not Intune Enrolled, it's out. So only 1 is left. A is correct. Comment 6 saying C might be referring to a different version of the question where Device 3 is actually Joined. Given the 100% vote for A and the strict requirements (Win 10/11, Entra Joined, Intune Enrolled), A is the most robust choice if Device 2 lacks Intune enrollment or Device 3 is Registered.

Why the Other Options Are Wrong

Options B, D, and E include devices that likely do not meet all three criteria (OS, Join Type, MDM). Option C includes Device3, which is typically Entra Registered in these scenarios, disqualifying it.

Community Comment Notes

User DiligentSam confirms the requirements are Windows 10/11, Entra Joined/Hybrid, and Intune Enrollment. User Knight_Of_Peace emphasizes that "Device must be Entra ID joined and Intune Enrolled." User Meek_Learner breaks down why Device3 (Registered) and Device4 (Android) are excluded, supporting the single-device conclusion.

Official Reference

Exam Strategy

Always verify the three pillars for EPM: OS (Win 10/11), Identity (Entra Joined/Hybrid), and Management (Intune/CM). Do not assume 'Registered' counts as 'Joined'.

Frequently Asked Questions

Why is an Entra Registered device ineligible for EPM?

EPM requires full management capabilities provided by Entra Joined or Hybrid Joined states. Registered devices lack the necessary policy enforcement and identity context for privilege escalation controls.

Does Android support Endpoint Privilege Management?

No, EPM is exclusively designed for Windows 10 and Windows 11 devices running on x64 or ARM64 architectures.

Related Analysis

Practice All MD-102 Questions

Access 92 questions with complete answers and detailed explanations.

View Full MD-102 Practice Test →

← Back to MD-102 Study Guide