MD 102 - Endpoint Administrator Associat…
HOTSPOT - You have a Microsoft Entra tenant that contains the groups shown in the following table. 


HOTSPOT - Your company has computers that run Windows 10 and are Microsoft Entra joined. The company purchases an Azure subscription. You need to collect Windows events from the Windows 10 computers in Azure. The solution must enable you to create alerts based on the collected events. What should you create in Azure and what should you configure on the computers? To answer, select the appropriate options in the answer area.
HOTSPOT - You have a Microsoft 365 subscription that contains the devices shown in the following table. 

HOTSPOT - You have a Microsoft 365 E5 subscription. You plan to create a Conditional Access policy named Policy1. You need to ensure that only Passwordless MFA authentication methods are used when administrators attempt to access the Azure portal, Azure PowerShell, or Azure Command- Line Interface (CLI). How should you configure Policy1? To answer, select the appropriate options in the answer area.
HOTSPOT - You have a Microsoft Entra tenant that contains the users shown in the following table. 

HOTSPOT - You have a Microsoft 365 E5 subscription that uses Microsoft Intune Suite. You need to recommend a solution that meets the following requirements: • Administrators must use a secure connection over a shared screen session to perform remote tasks on a user’ s device. • Administrators must have elevated access to perform remote tasks on a user ’s device. • The solution must follow the principle of least privilege. What should you include in the recommendation for each requirement? To answer, select the appropriate options in the answer area.
HOTSPOT - You have a Microsoft 365 E5 subscription that contains the devices shown in the following table. 

HOTSPOT - You use the Microsoft Deployment Toolkit (MDT) to deploy Windows 11. You need to modify the deployment share to meet the following requirements: • Ensure that the user who performs the installation is prompted to set the local Administrator password • Define a rule for how to name computers during the deployment. The solution must NOT replace the existing WinPE image. Which file should you modify for each requirement? To answer, select the appropriate options in the answer area,
HOTSPOT - You have a Microsoft 365 subscription and use the Microsoft Intune Suite. You have the devices shown in the following table. 
HOTSPOT - You have a Microsoft 365 subscription. You use Microsoft Intune Suite to manage devices. You have the iOS app protection policy shown in the following exhibit. 
HOTSPOT - You have a Microsoft 365 E5 subscription that contains the devices shown in the following table. 
HOTSPOT - Case study - Overview - ADatum Corporation is a consulting company that has a main office in Montreal and branch offices in Seattle and New York. ADatum has a Microsoft 365 E5 subscription. Environment - Network Environment - The network contains an on-premises Active Directory domain named adatum.com. The domain contains the servers shown in the following table. 






You have a Microsoft 365 subscription. You use Microsoft Intune to manage devices. You plan to deploy two apps named App1 and App2 to all Windows devices. App1 must be installed before App2. From the Intune admin center, you create and deploy two Windows app (Win32) apps. You need to ensure that App1 is installed before App2 on every device. What should you configure?
You have 200 computers that run Windows 10. The computers are joined to Azure AD and enrolled in Microsoft Intune. You need to enable self-service password reset on the sign-in screen. Which settings should you configure from the Microsoft Intune admin center?
You plan to deploy Windows 11 Pro to 200 new computers by using the Microsoft Deployment Toolkit (MDT) and Windows Deployment Services (WDS). The company has a Volume Licensing Agreement and uses a product key to activate Windows 11. You need to ensure that the new computers will be configured to have the correct product key during the installation. What should you configure?
You have a Microsoft 365 subscription that includes Microsoft Intune. The subscription contains Windows 11 devices enrolled in Intune. The subscription contains three groups named Departement1, Department2, and Department3. You need to deploy Microsoft 365 Apps to the Windows 11 devices. The solution must meet the following requirements: Users in Department1 and Department2 must receive the full Microsoft 365 Apps suite, including Microsoft Project and Visio. Users in Department3 must receive the full Microsoft 365 Apps suite, including Microsoft Project, but without Visio. All other users must receive the full Microsoft 365 Apps suite without Microsoft Project or Visio. What is the minimum number of deployments you should create?
You have a Windows 10 device named Device1 that is joined to Active Directory and enrolled in Microsoft Intune. Device1 is managed by using Group Policy and Intune. You need to ensure that the Intune settings override the Group Policy settings. What should you configure?
Your company has devices enrolled in Microsoft Intune as shown in the following table. 
You have a Microsoft 365 E5 subscription that contains 100 iOS devices enrolled in Microsoft Intune. You need to ensure that notifications of iOS updates are deferred for 30 days after the updates are released. What should you create?
You have a Microsoft 365 subscription. The subscription contains 500 computers that run Windows 11 and are enrolled in Microsoft Intune. You need to manage the deployment of monthly security updates. The solution must meet the following requirements: Updates must be deployed to a group of test computers for quality assurance. Updates must be deployed automatically 15 days after the quality assurance testing. What should you create in the Microsoft Intune admin center?
You have devices enrolled in Microsoft Intune as shown in the following table. 
You have a Microsoft Entra tenant named contoso.com. You purchase an Android device named Device1. You need to register Device1 in contoso.com. Solution: You use Microsoft Entra Connect. Does this meet the goal?
You have an Azure AD tenant named contoso.com. You plan to use Windows Autopilot to configure the Windows 10 devices shown in the following table. 
DRAG DROP - You have an on-premises Active Directory domain that syncs to Azure AD tenant. The tenant contains computers that run Windows 10. The computers are hybrid Azure AD joined and enrolled in Microsoft Intune. The Microsoft Office settings on the computers are configured by using a Group Policy Object (GPO). You need to migrate the GPO to Intune. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
DRAG DROP - You have a Microsoft 365 subscription that includes Microsoft Intune. You need to implement a Microsoft Defender for Endpoint solution that meets the following requirements: Enforces compliance for Defender for Endpoint by using Conditional Access Prevents suspicious scripts from running on devices What should you configure? To answer, drag the appropriate features to the correct requirements. Each feature may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
DRAG DROP - You have a Microsoft Deployment Toolkit (MDT) server named MDT1. When computers start from the LiteTouchPE_x64.iso image and connect to MDT1, the welcome screen appears as shown in the following exhibit. 
DRAG DROP - You have 100 computers that run Windows 10. You plan to deploy Windows 11 to the computers by performing a wipe and load installation. You need to recommend a method to retain the user settings and the user data. Which three actions should you recommend be performed in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
DRAG DROP - You have a Microsoft Intune subscription that is configured to use a PFX certificate connector to an on-premises Enterprise certification authority (CA). You need to use Intune to configure autoenrollment for Android devices by using public key pair (PKCS) certificates. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
DRAG DROP - Your company has a Microsoft 365 E5 tenant. All the devices of the company are enrolled in Microsoft Intune. You need to create advanced reports by using custom queries and visualizations from raw Microsoft Intune data. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
DRAG DROP - You have a Microsoft 365 subscription that contains 1,000 Windows 11 devices enrolled in Microsoft Intune. You plan to create and monitor the results of a compliance policy used to validate the BIOS version of the devices. Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
DRAG DROP - Your network contains an Active Directory domain. You install the Microsoft Deployment Toolkit (MDT) on a server. You have a custom image of Windows 11. You need to deploy the image to 100 devices by using MDT. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
DRAG DROP - You have 500 Windows 10 devices enrolled in Microsoft Intune. You plan to use Exploit protection in Microsoft Intune to enable the following system settings on the devices: • Data Execution Prevention (DEP) • Force randomization for images (Mandatory ASLR) You need to configure a Windows 10 device that will be used to create a template file. Which protection areas on the device should you configure in the Windows Security app before you create the template file? To answer, drag the appropriate protection areas to the correct settings. Each protection area may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
DRAG DROP - You have a computer that runs Windows 10 and contains two local users named User1 and User2. You need to ensure that the users can perform the following actions: User1 must be able to adjust the date and time. User2 must be able to clear Windows logs. The solution must use the principle of least privilege. To which group should you add each user? To answer, drag the appropriate groups to the correct users. Each group may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
DRAG DROP - You have a Microsoft 365 E5 subscription and a computer that runs Windows 11. You need to create a customized installation of Microsoft 365 Apps for enterprise. Which four actions should you perform in sequence? To answer, move the appropriate cmdlets from the list of cmdlets to the answer area and arrange them in the correct order.






















