Microsoft MD-101 Managing Modern Desktops Online Training
Microsoft MD-101 Online Training
The questions for MD-101 were last updated at Dec 20,2024.
- Exam Code: MD-101
- Exam Name: Managing Modern Desktops
- Certification Provider: Microsoft
- Latest update: Dec 20,2024
You have a Microsoft 365 subscription. All devices run Windows 10.
You need to prevent users from enrolling the devices in the Windows Insider Program.
What should you configure from Microsoft 365 Device Management? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
- A . a Windows 10 security baseline
- B . an app configuration policy
- C . a custom device configuration profile
- D . a Windows 10 update ring
- E . a device restrictions device configuration profile
DRAG DROP
Your network contains an Active Directory domain.
You install the Microsoft Deployment Toolkit (MDT) on a server
You have a custom image of Windows 10.
You need to deploy the image to 100 devices by using MDT.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the List of actions to the answer area and arrange them in the correct order.
Explanation:
Graphical user interface, text, application
Description automatically generated
HOTSPOT
You have 200 computers that run Windows 10.
You need to create a provisioning package to configure the following tasks:
✑ Remove the Microsoft News and the Xbox Microsoft Store apps.
✑ Add a VPN connection to the corporate network.
Which two customizations should you configure? To answer, select the appropriate customizations in the answer area. NOTE: Each correct selection is worth one point.
Explanation:
Connectivityprofiles
Policies
References:
https://docs.microsoft.com/en-us/windows/configuration/wcd/wcd-connectivityprofiles
https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-configuration-service-provider#applicationmanagement-applicationrestrictions
https://docs.microsoft.com/en-us/windows/configuration/wcd/wcd-policies
You have a Microsoft 365 subscription.
You are assigned the User administrator role.
An Azure AD security group named Group1 was deleted five days ago.
You need to restore Group1.
What should you do?
- A . Modify the group expiration policy.
- B . From Deleted groups, restore Group1.
- C . Manually recreate Group1.
- D . Ask a global administrator to restore Group1.
You use a Microsoft Intune subscription to manage iOS devices.
You configure a device compliance policy that blocks jailbroken iOS devices.
You need to enable Enhanced jailbreak detection.
What should you configure?
- A . the device compliance policy
- B . the Compliance policy settings
- C . a network location
- D . a configuration profile
A
Explanation:
Reference: https://docs.microsoft.com/en-us/mem/intune/protect/device-compliance-get-started
HOTSPOT
You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains a user named User1. User1 has a user principal name (UPN) of user1 @contoso.com.
You join a Windows 10 device named Client1 to contoso.com.
You need to add User1 to the local Administrators group of Client1.
How should you complete the command? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Explanation:
Box 1: net localgroup
Add user to group from command line (CMD)
Windows provides command line utilities to manager user groups. In this post, learn how to use the command net localgroup to add user to a group from command prompt’
For example to add a user ‘John’ to administrators group, we can run the below command.
net localgroup administrators John /add
Box 2: Contoso
The domain of the user is Contoso.
You need to assign the same deployment profile to all the computers that are configured by using Windows Autopilot.
Which two actions should you perform? Each correct answer presents part of the solution. NOTE: each correct selection is worth one point.
- A . Join the computers to Microsoft Azure Active Directory (Azure AD)
- B . Assign a Windows AutoPilot deployment profile to a group
- C . Join the computers to an on-premises Active Directory domain
- D . Create a Microsoft Azure Active Directory (Azure AD) group that has dynamic membership rules and uses the operatingSystem tag
- E . Create a Group Policy object (GPO) that is linked to a domain
- F . Create a Microsoft Azure Active Directory (Azure AD) group that has dynamic membership rules and uses the ZTDID tag
B,F
Explanation:
References: https://www.petervanderwoude.nl/post/automatically-assign-windows-autopilot-deployment-profile-to-windowsautopilot-devices/
HOTSPOT
Your company uses Microsoft Intune to manage Windows 10, Android, and iOS devices.
Several users purchase new iPads and Android devices.
You need to tell the users how to enroll their device in Intune.
What should you instruct the users to use for each device? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Explanation:
The Intune Company Portal app is used to enroll Android, iOS, macOS, and Windows devices
References:
https://docs.microsoft.com/en-us/intune-user-help/enroll-device-android-company-portal
https://docs.microsoft.com/en-us/intune-user-help/enroll-your-device-in-intune-ios
https://docs.microsoft.com/en-us/intune-user-help/enroll-your-device-in-intune-macos-cp
You have a Microsoft 365 tenant that contains the objects shown in the following table.
In the Microsoft Endpoint Manager admin center, you are creating a Microsoft 365 Apps app named App1.
To which objects can you assign App1?
- A . Admin1, Group3. and Group4 only
- B . Group1, Group2. Group3. and Group4 only
- C . Admin1, Group1, Group2. Group3, and Group4
- D . Group1, Group3, and Group4 only
- E . Group3 and Group4 only
D
Explanation:
Reference:
https://docs.microsoft.com/en-us/mem/intune/apps/apps-deploy
https://docs.microsoft.com/en-us/microsoft-365/admin/create-groups/compare-groups?view=o365-worldwide
HOTSPOT
Your network contains an Active Directory forest named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).
You use Microsoft Endpoint Configuration Manager for device management.
You have the Windows 10 devices shown in the following table.
You configure Endpoint Configuration Manager co-management as follows:
✑ Automatic enrollment in Intune: Pilot
✑ Pilot collection for all workloads: Collection2
You configure co-management workloads as shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Explanation:
Box 1: No
The Pilot Group does not include Device1.
Box 2: Yes
Box 3: Yes
The Pilot Group includes Device3.