Site icon Exam4Training

ADatum Corporation is a consulting company that has a main office in Montreal and branch offices in Seattle and New York

Testlet 2

Case study

Overview

ADatum Corporation is a consulting company that has a main office in Montreal and branch offices in Seattle and New York.

ADatum has a Microsoft 365 E5 subscription.

Environment

Network Environment

The network contains an on-premises Active Directory domain named adatum.com.

The domain contains the servers shown in the following table.

ADatum has a hybrid Azure AD tenant named adatum.com.

Users and Groups

The adatum.com tenant contains the users shown in the following table.

All users are assigned a Microsoft Office 365 license and an Enterprise Mobility + Security E3 license.

Enterprise State Roaming is enabled for Group1 and GroupA.

Group1 and Group2 have a Membership type of Assigned.

Devices

ADatum has the Windows 10 devices shown in the following table.

The Windows 10 devices are joined to Azure AD and enrolled in Microsoft Intune.

The Windows 10 devices are configured as shown in the following table.

All the Azure AD joined devices have an executable file named C:AppA.exe and a folder named D: Folder1.

Microsoft Intune Configuration

Microsoft Intune has the compliance policies shown in the following table.

The Automatic Enrolment settings have the following configurations:

• MDM user scope GroupA

• MAM user scope: GroupB

You have an Endpoint protection configuration profile that has the following Controlled folder access settings:

• Name: Protection1

• Folder protection: Enable

• List of apps that have access to protected folders: CVAppA.exe

• List of additional folders that need to be protected: D:Folderi1

• Assignments – Included groups: Group2, GroupB

Windows Autopilot Configuration

ADatum has a Windows Autopilot deployment profile configured as shown in the following exhibit.

Currently, there are no devices deployed by using Windows Autopilot.

The Intune connector for Active Directory is installed on Server1.

Contoso plans to implement the following changes:

• Purchase a new Windows 10 device named Device6 and enroll the device in Intune.

• New computers will be deployed by using Windows Autopilot and will be hybrid Azure AO joined.

• Deploy a network boundary configuration profile that will have the following settings:

– Name Boundary 1

– Network boundary 192.168.1.0/24

– Scope tags: Tag 1

– Assignments;

* included groups: Group 1. Group2

• Deploy two VPN configuration profiles named Connection! and Connection that will have the following settings:

– Name: Connection 1

– Connection name: VPNI

– Connection type: L2TP

– Assignments:

* Included groups: Group1. Group2, GroupA

* Excluded groups: ―

– Name: Connection

– Connection name: VPN2

– Connection type: IKEv2 i Assignments:

– included groups: GroupA

– Excluded groups: GroupB

Technical Requirements

Contoso must meet the following technical requirements:

• Users in GroupA must be able to deploy new computers.

• Administrative effort must be minimized.

HOTSPOT

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Box 1: No

User1 is a Cloud device administrator.

Local administrative privileges are required when enrolling an already configured Windows 10 device in Intune.

Cloud Device Administrator

Users in this role can enable, disable, and delete devices in Azure AD and read Windows 10 BitLocker keys (if present) in the Azure portal. The role does not grant permissions to manage any other properties on the device.

Note: The Windows 10 devices are joined to Azure AD and enrolled in Microsoft Intune.

Box 2: Yes

User2 is an Azure AD joined device local administrator.

Azure AD Joined Device Local Administrator

This role is available for assignment only as an additional local administrator in Device settings. Users with this role become local machine administrators on all Windows 10 devices that are joined to Azure Active Directory. They do not have the ability to manage devices objects in Azure Active Directory.

Box 3: No

User3 is a Global reader.

Global Reader

Users in this role can read settings and administrative information across Microsoft 365 services but can’t take management actions.

Reference: https://docs.microsoft.com/en-us/troubleshoot/mem/intune/no-permission-to-enroll-windows-devices

https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference

Latest MD-102 Dumps Valid Version with 98 Q&As

Latest And Valid Q&A | Instant Download | Once Fail, Full Refund

Exit mobile version