Microsoft MD-102 Übungsprüfungen
Zuletzt aktualisiert am 07.09.2025- Prüfungscode: MD-102
- Prüfungsname: Endpoint Administrator
- Zertifizierungsanbieter: Microsoft
- Zuletzt aktualisiert am: 07.09.2025
You have a Microsoft 365 tenant that contains the objects shown in the following table.
You are creating a compliance policy named Compliance1.
Which objects can you specify in Compliance1 as additional recipients of noncompliance notifications?
- A . Group3 and Group4 only
- B . Group3, Group4, and Admin1 only
- C . Group1, Group2, and Group3 only
- D . Group1, Group2, Group3, and Group4 only
- E . Group1, Group2, Group3, Group4, and Admin1
HOTSPOT
You have devices enrolled in Microsoft Intune as shown in the following table.
Intune includes the device compliance policies shown in the following table.
The device compliance policies has the assignments shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Hot Area:
Device1, Device2, and Device3
HOTSPOT
You have a Microsoft 365 E5 subscription that contains the devices shown in the following table.
The subscription contains the dynamic device groups shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Hot Area:
You need to assign the same deployment profile to all the computers that are configured by using Windows Autopilot.
Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
- A . Create a Microsoft Entra group that has dynamic membership rules and uses the ZTDID tag.
- B . Create a Microsoft Entra group that has dynamic membership rules and uses the operatingSystem tag.
- C . Assign a Windows Autopilot deployment profile to a group.
- D . Join the computers to Microsoft Entra.
- E . Create a Group Policy object (GPO) that is linked to a domain.
- F . Join the computers to an on-premises Active Directory domain.
You have a Microsoft Entra tenant named contoso.com.
You need to ensure that users are not added automatically to the local Administrators group when they join their Windows 11 device to contoso.com.
What should you configure?
- A . Windows Autopilot
- B . provisioning packages for Windows
- C . Security defaults in Microsoft Entra ID
- D . Device settings in Microsoft Entra ID
You have a Microsoft Entra tenant named contoso.com.
You need to ensure that users are not added automatically to the local Administrators group when they join their Windows 11 device to contoso.com.
What should you configure?
- A . Windows Autopilot
- B . provisioning packages for Windows
- C . Security defaults in Microsoft Entra ID
- D . Device settings in Microsoft Entra ID
You have a Microsoft Entra tenant named contoso.com.
You need to ensure that users are not added automatically to the local Administrators group when they join their Windows 11 device to contoso.com.
What should you configure?
- A . Windows Autopilot
- B . provisioning packages for Windows
- C . Security defaults in Microsoft Entra ID
- D . Device settings in Microsoft Entra ID
You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Azure AD joined and are enrolled in Microsoft Intune.
You plan to manage Microsoft Defender Antivirus on the computers. You need to prevent users from disabling Microsoft Defender Antivirus.
What should you do?
* From the Microsoft Intune admin center, create a security baseline.
* From the Microsoft 365 Defender portal, enable tamper protection.
* From the Microsoft Intune admin center, create an account protection policy.
* From the Microsoft Intune admin center, create an endpoint detection and response (EDR) policy.
Your network contains an on-premises Active Directory domain and an Azure AD tenant.
The Default Domain Policy Group Policy Object (GPO) contains the settings shown in the following table.
You need to migrate the existing Default Domain Policy GPO settings to a device configuration profile.
Which device configuration profile type template should you use?
- A . Administrative Templates
- B . Endpoint protection
- C . Device restrictions
- D . Custom