Capabilities of a User-Registered Device in Microsoft Entra ID
You have a Microsoft Entra tenant named contoso.com that contains a Windows 11 device named Device1 and a user named User1. User1 registers Device1 in contoso.com. Which capability is available to Device1 after registering in contoso.com?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the distinction between 'registration' and 'enrollment'; registration grants SSO access, while enrollment is required for compliance policies, updates, and encryption enforcement.
This question evaluates the specific capabilities granted to a Windows 11 device when registered as a user-owned device in a Microsoft Entra tenant. It establishes that registration primarily enables Single Sign-On (SSO) for cloud resources, distinct from full management features.
Many learners select 'Enforcing compliance policies' because they confuse user registration with full Intune enrollment. Registration alone does not allow the organization to enforce security policies like encryption or updates.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
When a user registers a personal device (BYOD) in Microsoft Entra ID, the primary capability granted is Single Sign-On (SSO). This allows the device to use its corporate identity to access cloud resources seamlessly without requiring full device management. The registration process links the device's local account to the Entra ID, enabling authentication flows.Why the Other Options Are Wrong
Options B, C, and D refer to capabilities that require the device to be enrolled in Microsoft Intune, not just registered. Enforcement of compliance policies, software updates, and hard drive encryption are managed via Intune configuration profiles and policies, which are not applied to devices that are only registered in Entra ID.Community Comment Notes
Community consensus strongly supports Option A, noting that SSO is the direct result of registration. One commenter noted that other options require configured policies, implying enrollment. Another dissenting view suggested compliance, but this is incorrect because conditional access checks compliance, but does not enforce it on a non-enrolled device.Exam Strategy
Always distinguish between 'register' (user-owned, limited access/SSO) and 'enroll' (organization-managed, full control/policies). If the question mentions 'register', think SSO and Conditional Access evaluation; if it mentions 'enroll', think policy enforcement and remote actions.
Frequently Asked Questions
Can a registered device be subject to Conditional Access?
Yes, Conditional Access policies can evaluate device state (registered vs. compliant), but the device itself cannot enforce policies like encryption.
What is the difference between registration and enrollment?
Registration links the device to Entra ID for SSO; Enrollment adds the device to Intune for management and policy enforcement.
Related Analysis
Practice All MD-102 Questions
Access 92 questions with complete answers and detailed explanations.
View Full MD-102 Practice Test →