You have devices enrolled in Microsoft Intune as shown in the following table.
For which devices can you manage updates by using Intune?
Free MD 102 Practice Test Questions and Answers (2026)
DRAG DROP - You have a Microsoft 365 subscription. The subscription contains computers that run Windows 11 and are enrolled in Microsoft Intune. You need to create a compliance policy that meets the following requirements: Requires BitLocker Drive Encryption (BitLocker) on each device Requires a minimum operating system version Which setting of the compliance policy should you configure for each requirement? To answer, drag the appropriate settings to the correct requirements. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
HOTSPOT - You have a Microsoft 365 E5 subscription that uses Microsoft Intune. You have the Windows 11 devices shown in the following table. 

DRAG DROP - You have a Microsoft Deployment Toolkit (MDT) deployment share named DS1. You import a Windows 11 image to DS1. You have an executable installer for an application named App1. You need to ensure that App1 will be installed for all the task sequences that deploy the image. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
HOTSPOT - You have a Microsoft 365 E5 subscription. You need to review and implement Microsoft 365 Defender device onboarding. The solution must meet the following requirements: View onboarded devices that have the Chromium-based version for Microsoft Edge installed. Download an onboarding package for a Windows 11 device. Minimize administrative effort. Which two settings should you use in the Microsoft 365 Defender portal? To answer, select the appropriate settings in the answer area.
You have a Microsoft 365 subscription that uses Microsoft Intune Suite. You use Intune to manage all devise. Users have iOS devices with Microsoft apps installed. You need to prevent users from cutting, copying, and pasting data between Microsoft Excel and other apps installed on the devices. What should you configure?
Your company has an Azure AD tenant named contoso.com that contains several Windows 10 devices. When you join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin. You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com. Solution: From the Microsoft Entra admin center, you modify the User settings and the Device settings. Does this meet the goal?
You have a Microsoft 365 E5 subscription that contains 100 iOS devices enrolled in Microsoft Intune. You need to deploy a custom line-of-business (LOB) app to the devices by using Intune. Which extension should you select for the app package file?
HOTSPOT - You have a Microsoft 365 E5 subscription that uses Microsoft Intune. The subscription contains the resources shown in the following table. 

You have a Microsoft 365 E5 subscription. You purchase the following types of devices: • Windows • Android • iOS You plan to enroll the devices in Microsoft Intune. You need to configure enrollment restrictions. For which device types can you configure device manufacturer restrictions?
You have an on-premises server named Server1 that hosts a Microsoft Deployment Toolkit (MDT) deployment share named MDT1. You need to ensure that MDT1 supports multicast deployments. What should you install on Server1?
DRAG DROP - You have a Microsoft 365 subscription that includes Microsoft Intune. You need to implement a Microsoft Defender for Endpoint solution that meets the following requirements: Enforces compliance for Defender for Endpoint by using Conditional Access Prevents suspicious scripts from running on devices What should you configure? To answer, drag the appropriate features to the correct requirements. Each feature may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
DRAG DROP - You have a computer that runs Windows 10 and contains two local users named User1 and User2. You need to ensure that the users can perform the following actions: User1 must be able to adjust the date and time. User2 must be able to clear Windows logs. The solution must use the principle of least privilege. To which group should you add each user? To answer, drag the appropriate groups to the correct users. Each group may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
HOTSPOT - You have a Microsoft 365 subscription. You need to enable passwordless authentication for all users. The solution must meet the following requirements: Users in the research department cannot use mobile devices and must authenticate from unmanaged Linux devices by using an alternative method. To access services, users in the sales department must authenticate by using their mobile phone. Administrative effort must be minimized. Which authentication method should you use for each department? To answer, select the appropriate options in the answer area.
SIMULATION - Username and password - Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and select the username below. To enter your password, place your cursor in the Enter password box and select the password below. Microsoft 365 Username: [email protected] Microsoft 365 Password: i7A4$3o^HGD3L~=c[9xuOhM%^4:s11Ai If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL “https://portal.office.com”, and press Enter. The following information is for technical support purposes only: Lab Instance: 48262079 - You need to join your computer to the Microsoft Entra tenant.
HOTSPOT - Case study - Overview - Contoso, Ltd. is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York. Contoso has the users and computers shown in the following table. 





What's covered in this practice questions set
3: Manage, maintain, and protect devices · 11 questions
📖 About this Domain
This domain focuses on the day-to-day operational tasks for endpoint lifecycle management. It covers device configuration, software update servicing, endpoint monitoring, and implementing security controls using Microsoft Intune and related services.
🎓 What You Will Learn
- How to manage device configuration by using configuration profiles, settings catalog, and Group Policy analytics in Microsoft Intune.
- The process for managing the Windows update lifecycle using Windows Update for Business deployment rings and feature update policies.
- Methods to monitor device health and compliance using Intune reports, Endpoint analytics, and Azure Monitor.
- Techniques to protect endpoints by deploying security baselines, BitLocker disk encryption, and Microsoft Defender policies.
🛠️ Skills You Will Build
- Deploying and troubleshooting device configuration profiles to enforce organizational standards across diverse endpoints.
- Implementing a robust update servicing strategy for Windows devices to ensure timely patching and feature adoption.
- Analyzing endpoint health and performance data to proactively identify and remediate device issues.
- Hardening device security posture by applying and managing endpoint protection policies through the Intune admin center.
💡 Top Tips to Prepare
- Practice creating and assigning configuration profiles and compliance policies in a Microsoft 365 developer tenant.
- Memorize the different servicing channels and deferral settings for Windows Update for Business.
- Navigate the Endpoint analytics and Intune reports to understand key metrics like startup performance and app reliability.
- Understand the relationship between Intune, Microsoft Defender for Endpoint, and Conditional Access for enforcing device compliance.
1: Deploy Windows client · 4 questions
📖 About this Domain
This domain covers Windows client OS deployment and configuration. It emphasizes modern deployment methods like Windows Autopilot and traditional methods like Microsoft Deployment Toolkit (MDT). You will also manage device activation and subscriptions.
🎓 What You Will Learn
- Assess infrastructure readiness and select deployment tools like MDT or Windows Autopilot.
- Configure Windows Autopilot deployment profiles, enrollment status pages (ESP), and manage device registration.
- Create and manage OS images, task sequences, and deployment shares using MDT for bare-metal deployments.
- Enable and configure remote management tools including Windows Admin Center and PowerShell Remoting.
🛠️ Skills You Will Build
- Perform zero-touch provisioning of Windows devices using Windows Autopilot profiles and device hashes.
- Execute image-based deployments by creating, capturing, and deploying custom WIM files with MDT and DISM.
- Manage Windows Enterprise subscriptions and implement subscription activation policies for endpoint licensing.
- Remotely administer endpoints post-deployment using Windows Admin Center and WinRM.
💡 Top Tips to Prepare
- Gain hands-on lab experience registering device hashes and testing various Autopilot deployment profiles.
- Deconstruct and build MDT task sequences to understand driver injection, application installation, and USMT integration.
- Memorize the differences between KMS, MAK, and subscription-based activation for licensing scenarios.
- Complete the official Microsoft Learn modules for MD-102 focusing on operating system deployment and updates.
2: Manage identity and compliance · 3 questions
📖 About this Domain
This domain covers managing device and user identities in Microsoft Entra ID. It focuses on implementing compliance policies and security baselines using Microsoft Intune. You will also configure core endpoint security features to protect organizational data.
🎓 What You Will Learn
- You will learn to manage Microsoft Entra device identities, including registration and join processes for Windows endpoints.
- You will learn to implement Conditional Access policies to enforce access controls based on user, device, and location signals.
- You will learn to configure and deploy device compliance policies in Microsoft Intune to validate endpoint health and configuration.
- You will learn to manage endpoint security profiles, including BitLocker disk encryption and Microsoft Defender Antivirus settings.
🛠️ Skills You Will Build
- You will build skills to join devices to Microsoft Entra ID and configure local user and group policies.
- You will build skills to create and assign Conditional Access policies that require multifactor authentication (MFA) or compliant devices.
- You will build skills to deploy Intune compliance policies and configure notifications and actions for noncompliance.
- You will build skills to enforce disk encryption using BitLocker policies and manage security baselines for endpoints.
💡 Top Tips to Prepare
- Practice configuring Microsoft Entra join and Microsoft Entra hybrid join in a test tenant to understand the prerequisites.
- Master the components of a Conditional Access policy, specifically the relationship between assignments, conditions, and access controls.
- Understand the integration between Intune compliance policies and Conditional Access to block noncompliant devices from resources.
- Get hands-on experience in the Microsoft Intune admin center deploying security baselines and endpoint protection profiles.
4: Manage applications · 2 questions
📖 About this Domain
This domain covers the lifecycle management of applications on endpoints. You will focus on deploying, updating, and securing applications using Microsoft Intune and Microsoft 365 services. Key areas include application deployment strategies, policy enforcement, and application control.
🎓 What You Will Learn
- Learn to deploy various application types, including Win32 apps and Microsoft 365 Apps, using Microsoft Intune.
- Understand how to configure and assign Application Protection Policies (APP) and Application Configuration Policies (ACP) to protect corporate data.
- Explore managing Microsoft 365 Apps deployments and updates through the dedicated Microsoft 365 Apps admin center.
- Discover how to implement application control using Microsoft Defender Application Control and AppLocker to restrict application execution.
🛠️ Skills You Will Build
- You will build proficiency in packaging, deploying, and troubleshooting Win32 applications and LOB apps with Intune.
- You will gain skills in creating and targeting app protection and configuration policies to manage app behavior and data security.
- You will develop the ability to create and enforce AppLocker and Microsoft Defender Application Control policies for endpoint hardening.
- You will learn to manage update channels, servicing profiles, and inventory for Microsoft 365 Apps across the enterprise.
💡 Top Tips to Prepare
- Gain hands-on experience by packaging a Win32 app with the Microsoft Win32 Content Prep Tool and deploying it via Intune.
- Clearly differentiate between Application Protection Policies (APP) for data protection and Application Configuration Policies (ACP) for app settings.
- Study the differences, use cases, and implementation methods for AppLocker versus Microsoft Defender Application Control.
- Familiarize yourself with the Microsoft 365 Apps admin center dashboard, focusing on inventory, security updates, and servicing profiles.








