Microsoft MD-102 Endpoint Administrator Online Training
Microsoft MD-102 Online Training
The questions for MD-102 were last updated at Feb 20,2025.
- Exam Code: MD-102
- Exam Name: Endpoint Administrator
- Certification Provider: Microsoft
- Latest update: Feb 20,2025
Testlet 1
Case study
Overview
Contoso, Ltd. is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York.
Contoso has the users and computers shown in the following table.
The company has IT, human resources (HR), legal (LEG), marketing (MKG), and finance (FIN) departments.
Contoso recently purchased a Microsoft 365 subscription.
The company is opening a new branch office in Phoenix. Most of the users in the Phoenix office will work from home.
Existing Environment
The network contains an Active Directory domain named contoso.com that is synced to Azure AD.
All member servers run Windows Server 2016. All laptops and desktop computers run Windows 10 Enterprise.
The computers are managed by using Microsoft Configuration Manager. The mobile devices are managed by using Microsoft Intune.
The naming convention for the computers is the department acronym, followed by a hyphen, and then four numbers, for example FIN-6785. All the computers are joined to the on-premises Active Directory domain.
Each department has an organizational unit (OU) that contains a child OU named Computers. Each computer account is in the Computers OU of its respective department.
Intune Configuration
Requirements
Planned changes
Contoso plans to implement the following changes:
– Provide new computers to the Phoenix office users. The new computers have Windows 10 Pro preinstalled and were purchased already.
– Implement co-management for the computers.
Technical Requirements
Contoso must meet the following technical requirements:
– Ensure that the users in a group named Group4 can only access Microsoft Exchange Online from devices that are enrolled in Intune.
– Deploy Windows 10 Enterprise to the computers of the Phoenix office users by using Windows Autopilot.
– Create a provisioning package for new computers in the HR department.
– Block iOS devices from sending diagnostic and usage telemetry data.
– Use the principle of least privilege whenever possible.
– Enable the users in the MKG department to use App1.
– Pilot co-management for the IT department.
You need to prepare for the deployment of the Phoenix office computers.
What should you do first?
- A . Generalize the computers and configure the Device settings from the Microsoft Entra admin center.
- B . Extract the serial number of each computer to an XML file and upload the file from the Microsoft Intune admin center.
- C . Extract the hardware ID information of each computer to a CSV file and upload the file from the Microsoft Intune admin center.
- D . Generalize the computers and configure the Mobility (MDM and MAM) settings from the Microsoft Entra admin center.
- E . Extract the serial number information of each computer to a CSV file and upload the file from the Microsoft Intune admin center.
HOTSPOT
What is the maximum number of devices that User1 and User2 can enroll in Intune? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Testlet 2
Case study
Overview
ADatum Corporation is a consulting company that has a main office in Montreal and branch offices in Seattle and New York.
ADatum has a Microsoft 365 E5 subscription.
Environment
Network Environment
The network contains an on-premises Active Directory domain named adatum.com.
The domain contains the servers shown in the following table.
ADatum has a hybrid Azure AD tenant named adatum.com.
Users and Groups
The adatum.com tenant contains the users shown in the following table.
All users are assigned a Microsoft Office 365 license and an Enterprise Mobility + Security E3 license.
Enterprise State Roaming is enabled for Group1 and GroupA.
Group1 and Group2 have a Membership type of Assigned.
Devices
ADatum has the Windows 10 devices shown in the following table.
The Windows 10 devices are joined to Azure AD and enrolled in Microsoft Intune.
The Windows 10 devices are configured as shown in the following table.
All the Azure AD joined devices have an executable file named C:AppA.exe and a folder named D: Folder1.
Microsoft Intune Configuration
Microsoft Intune has the compliance policies shown in the following table.
The Automatic Enrolment settings have the following configurations:
• MDM user scope GroupA
• MAM user scope: GroupB
You have an Endpoint protection configuration profile that has the following Controlled folder access settings:
• Name: Protection1
• Folder protection: Enable
• List of apps that have access to protected folders: CVAppA.exe
• List of additional folders that need to be protected: D:Folderi1
• Assignments – Included groups: Group2, GroupB
Windows Autopilot Configuration
ADatum has a Windows Autopilot deployment profile configured as shown in the following exhibit.
Currently, there are no devices deployed by using Windows Autopilot.
The Intune connector for Active Directory is installed on Server1.
Contoso plans to implement the following changes:
• Purchase a new Windows 10 device named Device6 and enroll the device in Intune.
• New computers will be deployed by using Windows Autopilot and will be hybrid Azure AO joined.
• Deploy a network boundary configuration profile that will have the following settings:
– Name Boundary 1
– Network boundary 192.168.1.0/24
– Scope tags: Tag 1
– Assignments;
* included groups: Group 1. Group2
• Deploy two VPN configuration profiles named Connection! and Connection that will have the following settings:
– Name: Connection 1
– Connection name: VPNI
– Connection type: L2TP
– Assignments:
* Included groups: Group1. Group2, GroupA
* Excluded groups: ―
– Name: Connection
– Connection name: VPN2
– Connection type: IKEv2 i Assignments:
– included groups: GroupA
– Excluded groups: GroupB
Technical Requirements
Contoso must meet the following technical requirements:
• Users in GroupA must be able to deploy new computers.
• Administrative effort must be minimized.
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
You need to ensure that computer objects can be created as part of the Windows Autopilot deployment.
The solution must meet the technical requirements.
To what should you grant the right to create the computer objects?
- A . Server1
- B . DC1
- C . GroupA
- D . Server2
Which user can enroll Device6 in Intune?
- A . User4 and User1 only
- B . User4 and User2 only
- C . User4, User1, and User2 only
- D . User1, User2, User3, and User4
You have a Microsoft 365 E5 subscription. The subscription contains 25 computers that run Windows 11 and are enrolled in Microsoft Intune.
You need to onboard the devices to Microsoft Defender for Endpoint.
What should you create in the Microsoft Intune admin center?
- A . an attack surface reduction (ASR) policy
- B . a security baseline
- C . an endpoint detection and response (EDR) policy
- D . an account protection policy
- E . an antivirus policy
Your company uses Microsoft Intune to manage devices.
You need to ensure that only Android devices that use Android work profiles can enroll in Intune.
Which two configurations should you perform in the device enrollment restrictions? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
- A . From Platform Settings, set Android device administrator Personally Owned to Block.
- B . From Platform Settings, set Android Enterprise (work profile) to Allow.
- C . From Platform Settings, set Android device administrator Personally Owned to Allow.
- D . From Platform Settings, set Android device administrator to Block.
Your company uses Microsoft Intune to manage devices.
You need to ensure that only Android devices that use Android work profiles can enroll in Intune.
Which two configurations should you perform in the device enrollment restrictions? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
- A . From Platform Settings, set Android device administrator Personally Owned to Block.
- B . From Platform Settings, set Android Enterprise (work profile) to Allow.
- C . From Platform Settings, set Android device administrator Personally Owned to Allow.
- D . From Platform Settings, set Android device administrator to Block.
Your company uses Microsoft Intune to manage devices.
You need to ensure that only Android devices that use Android work profiles can enroll in Intune.
Which two configurations should you perform in the device enrollment restrictions? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
- A . From Platform Settings, set Android device administrator Personally Owned to Block.
- B . From Platform Settings, set Android Enterprise (work profile) to Allow.
- C . From Platform Settings, set Android device administrator Personally Owned to Allow.
- D . From Platform Settings, set Android device administrator to Block.
HOTSPOT
You have 100 Windows 10 devices enrolled in Microsoft Intune.
You need to configure the devices to retrieve Windows updates from the internet and from other computers on a local network.
Which Delivery Optimization setting should you configure, and which type of Intune object should you create? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.