MD-102 Sample Questions

MD-102 Sample Questions & Answers

Deploying and configuring Windows clients plus Intune Suite add-ons carries the most weight, alongside protecting devices with endpoint security and updates, preparing the infrastructure by enrolling devices, and managing application deployment and policies.

Launch the full MD-102 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Prepare infrastructure for devices · Implement and manage Local Administrative Passwords Solution (LAPS) for Microsoft Entra ID

    A company is migrating its local administrator password management to Microsoft Entra LAPS. An administrator needs to retrieve the password for a specific device, DESKTOP-ABC, to perform a maintenance task. The administrator has been assigned the 'Cloud Device Administrator' role in Microsoft Entra ID. Where can the administrator retrieve the LAPS password for DESKTOP-ABC?

    Show answer & explanation

    Correct answer: B

    With the correct permissions (such as Cloud Device Administrator or Intune Administrator), the LAPS password for a Microsoft Entra joined device can be retrieved from both the Microsoft Entra admin center and the Microsoft Intune admin center. On the device's object page in either portal, there is a 'Local administrator password' blade or option to view the password. This is the primary location for administrative retrieval.

  2. Question 2Intermediate

    Manage and maintain devices · Target a profile by using filters

    You are creating a filter in Microsoft Intune to target a device configuration profile to only corporate-owned Windows devices that are part of the marketing department. The department information is stored in the department device property. Which rule syntax should you use for this filter?

    Show answer & explanation

    Correct answer: A

    The correct syntax for an Intune filter rule uses the device or user prefix, followed by the property name. The -eq operator is used for equality checks, and the -and operator combines multiple conditions. Therefore, (device.deviceOwnership -eq "Corporate") -and (device.department -eq "Marketing") correctly targets devices that meet both criteria.

  3. Question 3Intermediate

    Protect devices · Configure Windows client delivery optimization by using Intune

    A global organization wants to optimize the delivery of Windows quality updates to its branch offices, which have limited WAN bandwidth. The goal is to have devices in each office share update content with each other before downloading from the internet. The network is segmented by subnet. What is the most effective Delivery Optimization download mode to configure in Intune to achieve this?

    Show answer & explanation

    Correct answer: C

    Download mode 2, 'Group', is the most effective choice. It restricts peer sharing to devices within the same group. When you configure the 'Select the source of group IDs' setting to use the AD Site or a DHCP option, devices in the same physical location (branch office) can form a peer group and share content efficiently over the LAN, significantly reducing WAN bandwidth consumption.

  4. Question 4Beginner

    Prepare infrastructure for devices · Configure enrollment profiles for Android devices

    A hospital is deploying dedicated Android Enterprise devices for patient check-in. These devices must be locked down to a single application and require a secure method of enrollment that can be easily performed by non-technical staff. The devices are new and will be unboxed on-site. Which enrollment method should be used?

    Show answer & explanation

    Correct answer: C

    For dedicated devices (kiosk mode), enrollment using a QR code is ideal for on-site, bulk provisioning by non-technical staff. From the factory reset screen, tapping the screen multiple times initiates the QR code scanner. Scanning the QR code generated from the Intune enrollment profile automates the Wi-Fi connection, agent download, and enrollment process into dedicated device mode.

  5. Question 5Intermediate

    Manage applications · Prepare applications for deployment by using Intune

    You are packaging a complex Win32 application for deployment via Intune. The application has a dependency on the .NET Framework 4.8 runtime. You need to ensure the .NET Framework is installed before the main application attempts to install. How should you configure this in the Win32 app properties in Intune?

    Show answer & explanation

    Correct answer: C

    The 'Dependencies' feature for Win32 apps in Intune is designed for this exact scenario. You must first package and upload the .NET Framework 4.8 as a separate Win32 app. Then, when configuring the main application, you can add the .NET Framework app as a dependency and configure it to automatically install. Intune will then process the dependency chain, ensuring the framework is installed before the main application.

  6. Question 6AdvancedSelect 3

    Prepare infrastructure for devices · Implement Conditional Access policies that require a compliance status

    You are an endpoint administrator for a company that has adopted a Zero Trust security model. You need to create a Conditional Access policy that requires users accessing SharePoint Online from unmanaged Windows devices to use an app-protected browser and prevents them from downloading files. Which three conditions and controls should you configure? (Select THREE)

    Show answer & explanation

    Correct answers: A, B, D

    This condition correctly targets unmanaged devices by excluding devices that are known to be managed and compliant.

    This condition ensures the policy applies specifically to browser-based access to SharePoint Online.

    This session control integrates with Microsoft Defender for Cloud Apps to enforce granular controls like blocking downloads, which is a key requirement for protecting data on unmanaged devices.

  7. Question 7Advanced

    Manage and maintain devices · Run a device query by using KQL

    A company has onboarded all its Windows 11 devices to Microsoft Defender for Endpoint. An administrator needs to write a Kusto Query Language (KQL) query to find all devices that have executed powershell.exe in the last 7 days and display the device name and the user who initiated the process. Which KQL query should the administrator use?

    Show answer & explanation

    Correct answer: B

    The correct table for process creation events in Microsoft Defender for Endpoint is DeviceProcessEvents. The query correctly filters for FileName == "powershell.exe", limits the time range with Timestamp > ago(7d), and then uses project to select the required columns: DeviceName and InitiatingProcessAccountName.

  8. Question 8Intermediate

    Manage applications · Plan and implement app protection policies

    Case Study:
    Contoso, Ltd. is a manufacturing company with 5,000 employees, expanding its use of Microsoft 365 and Intune. They have a mix of corporate-owned Windows 11 laptops and a BYOD program for iOS and Android mobile devices.

    Current Environment:
    Contoso uses a hybrid Microsoft Entra ID setup, with an on-premises Active Directory synced to the cloud. All corporate Windows devices are Hybrid Azure AD Joined. The BYOD devices are currently unmanaged. Intune has been configured as the MDM authority.

    Requirements:

    1. Windows Devices: All new corporate laptops must be deployed using Windows Autopilot user-driven mode. These devices need to be provisioned with Microsoft 365 Apps, Microsoft Teams, and a proprietary line-of-business (LOB) Win32 app before the user accesses the desktop.
    2. BYOD Policy: For personal iOS and Android devices, Contoso wants to protect corporate data within Outlook and OneDrive without enrolling the devices into MDM. Users should be prevented from copying data from these apps to personal apps like Gmail or Dropbox.
    3. Security: All corporate Windows devices must have disk encryption enabled and be protected by a standard set of firewall rules defined by the security team. Devices that are not encrypted must be marked as non-compliant and blocked from accessing corporate resources.

    Problem:
    You need to design an Intune implementation that meets all of Contoso's requirements. Which Intune policy type should be used to enforce the data protection rules for the BYOD devices?

    Show answer & explanation

    Correct answer: C

    The requirement is to protect corporate data on personal BYOD devices without enrolling them in MDM. This is the primary use case for App Protection Policies, also known as Mobile Application Management (MAM) without enrollment. These policies can control data transfer (like cut/copy/paste) between managed corporate apps (Outlook, OneDrive) and unmanaged personal apps, directly addressing the requirement.

  9. Question 9Advanced

    Manage and maintain devices · Implement a Windows 365 cloud PC deployment

    Your organization is deploying Windows 365 Cloud PCs to a group of developers. To improve security, you want to ensure that all network traffic from the Cloud PCs to the internet is routed through the corporate on-premises network for inspection. Which component must be configured to achieve this?

    Show answer & explanation

    Correct answer: A

    To route all internet-bound traffic from Windows 365 Cloud PCs back to an on-premises network, you must configure an Azure network connection (ANC). This ANC needs to be linked to an Azure Virtual Network that has a connection to the on-premises network via VPN or ExpressRoute. Critically, forced tunneling must be enabled on this connection, which directs all traffic, including internet-bound traffic, through the on-premises gateway for inspection.

  10. Question 10Beginner

    Protect devices · Plan and implement security baselines

    You have deployed a security baseline for Windows 11 to all corporate devices. Later, you create a device configuration profile from the Settings Catalog that configures a specific password setting differently than the baseline. Both policies are assigned to the same device group. Which policy will take precedence on the devices?

    Show answer & explanation

    Correct answer: B

    In Microsoft Intune, when there is a conflict between a security baseline and another policy type (like a device configuration profile or a compliance policy), the setting that is NOT in the baseline takes precedence. Security baselines are considered a starting point, and more specific, granular configurations made in other profiles are designed to override the baseline settings. This allows for flexibility while maintaining a standard security posture.

Ready for the real thing?

The full MD-102 simulator has every exam-style question, timed mode, and instant scoring.

Go to the MD-102 simulator →