Microsoft MD-102 Endpoint Administrator Online Training
Microsoft MD-102 Online Training
The questions for MD-102 were last updated at Nov 23,2024.
- Exam Code: MD-102
- Exam Name: Endpoint Administrator
- Certification Provider: Microsoft
- Latest update: Nov 23,2024
Your company has an Azure AD tenant named contoso.com that contains several Windows 10 devices.
When you join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin.
You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com.
Solution: From the Microsoft Entra admin center, you configure automatic mobile device management (MDM) enrollment. From the Microsoft Intune admin center, you configure the Windows Hello for Business enrollment options.
Does this meet the goal?
- A . Yes
- B . No
HOTSPOT
You have an Azure AD tenant that contains the users shown in the following table.
You have the devices shown in the following table.
You have a Conditional Access policy named CAPolicy1 that has the following settings:
• Assignments
o Users or workload identities: User 1. User1
o Cloud apps or actions: Office 365 Exchange Online o Conditions: Device platforms: Windows, iOS
• Access controls
o Grant Require multi-factor authentication
You have a Conditional Access policy named CAPolicy2 that has the following settings:
Assignments
o Users or workload identities: Used, User2
o Cloud apps or actions: Office 365 Exch
o Conditions
â– Device platforms: Android, iOS
â– Filter for devices
â– Device matching the rule: Exclude filtered devices from policy
â– Rule syntax: device. displayName- contains "1"
â– Access controls
â– Grant Block access
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
HOTSPOT
You have a Microsoft 365 subscription that contains the devices shown in the following table.
You plan to enroll the devices in Microsoft Intune.
How often will the compliance policy check-ins run after each device is enrolled in Intune? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
You have a Microsoft 365 E5 subscription that contains 500 macOS devices enrolled in Microsoft Intune.
You need to ensure that you can apply Microsoft Defender for Endpoint antivirus policies to the macOS devices. The solution must minimize administrative effort.
What should you do?
- A . From the Microsoft Endpoint Manager admin center, create a configuration profile.
- B . From the Microsoft Endpoint Manager admin center, create a security baseline.
- C . Onboard the macOS devices to the Microsoft 365 compliance center.
- D . Install Defender for Endpoint on the macOS devices.
HOTSPOT
You have the on-premises servers shown in the following table.
You have a Microsoft 365 E5 subscription that contains Android and iOS devices. All the devices are managed by using Microsoft Intune.
You need to implement Microsoft Tunnel for Intune. The solution must minimize the number of open firewall ports.
To which server can you deploy a Tunnel Gateway server, and which inbound ports should be allowed on the server to support Microsoft Tunnel connections? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
HOTSPOT
You have an Azure Active Directory Premium Plan 2 subscription that contains the users shown in the following table.
You purchase the devices shown in the following table.
You configure automatic mobile device management (MDM) and mobile application management (MAM) enrollment by using the following settings:
– MDM user scope: Group1
– MAM user scope: Group2
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Your company has devices enrolled in Microsoft Intune as shown in the following table.
In Microsoft Endpoint Manager, you define the company’s network as a location named Location1.
Which devices can use network location-based compliance policies?
- A . Device2 and Device3 only
- B . Device2 only
- C . Device1 and Device2 only
- D . Device1 only
- E . Device1, Device2, and Device3
You use Microsoft Intune and Intune Data Warehouse.
You need to create a device inventory report that includes the data stored in the data warehouse.
What should you use to create the report?
- A . the Azure portal app
- B . Endpoint analytics
- C . the Company Portal app
- D . Microsoft Power Bl
HOTSPOT
You have a Microsoft 365 tenant and an internal certification authority (CA).
You need to use Microsoft Intune to deploy the root CA certificate to managed devices.
Which type of Intune policy and profile should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
You have a Microsoft 365 E5 subscription that contains the groups shown in the following table.
You create a Conditional Access policy named CAPolicy1 that will block access to Microsoft Exchange Online from iOS devices. You assign CAPolicy1 to Group1.
You discover that User1 can still connect to Exchange Online from an iOS device.
You need to ensure that CAPolicy1 is enforced.
What should you do?
- A . Configure a new terms of use (TOU).
- B . Assign CAPolicy1 to Group2.
- C . Enable CAPolicy1
- D . Add a condition in CAPolicy1 to filter for devices.