Microsoft 365 Endpoint Administrator practice questions
205 free questions with answers and explanations.
- 1.A Microsoft 365 Endpoint Administrator needs to configure Microsoft Intune to apply specific security settings to devices based on their geographical location. For example, devices accessing corporate data from outside the corporate network should have a stricter set of security policies applied. Which feature in Microsoft Intune should the administrator use to achieve this dynamic policy application?Manage identity and compliance (10-15%)
- 2.A Microsoft 365 Endpoint Administrator wants to ensure that users can only access corporate resources from specific IP ranges within the company's network. If a user attempts to access resources from outside these IP ranges, access should be blocked. Which Conditional Access condition should be configured?Manage identity and compliance (10-15%)
- 3.An organization needs to ensure that all user-generated content in Microsoft Teams, including chat messages and files, is retained for a minimum of five years for compliance reasons. After five years, the content should be automatically deleted. Which compliance feature in Microsoft 365 should you configure?Manage identity and compliance (10-15%)
- 4.A company policy requires that all documents saved to OneDrive for Business from corporate-managed Windows devices must be encrypted. You need to implement a solution that automatically enforces this encryption for new and existing files. Which Microsoft 365 compliance feature should you configure?Manage identity and compliance (10-15%)
- 5.A company is implementing a Zero Trust security model. They want to ensure that access to highly sensitive applications is only granted from devices that are considered 'trusted'. For Windows 11 devices, this means they must be Azure AD joined and compliant with Intune policies. Which type of Conditional Access grant control should be configured?Manage identity and compliance (10-15%)
- 6.A user reports that they cannot access a specific SharePoint Online site from their personal laptop, which is not enrolled in Intune. The error message indicates that their device does not meet the organization's compliance requirements. You have already verified that the user's account is enabled and has the correct permissions to the SharePoint site. Which policy type is most likely preventing access?Manage identity and compliance (10-15%)
- 7.An administrator needs to configure Intune to automatically enroll all new corporate-owned iOS/iPadOS devices without requiring user interaction during the initial setup. The devices are purchased directly from Apple. Which enrollment method should be used?Manage identity and compliance (10-15%)
- 8.A user reports that they are unable to access a specific internal web application from their personal, non-compliant device. The Conditional Access policy for this application requires devices to be 'compliant' and 'managed'. Which setting in the Conditional Access policy is most likely preventing their access?Manage identity and compliance (10-15%)
- 9.A company needs to ensure that all Microsoft Teams chat messages, including private chats and channel messages, are retained for a minimum of five years for regulatory compliance. After this period, they should be automatically deleted. Which Microsoft Purview feature should be configured?Manage identity and compliance (10-15%)
- 10.A company policy requires that all corporate-owned Android devices must have a work profile for separating corporate and personal data. Additionally, all apps installed within the work profile must be approved by IT. Which Intune enrollment profile should be used for these devices?Manage identity and compliance (10-15%)
- 11.A Microsoft 365 Endpoint Administrator needs to deploy a custom PowerShell script to all Windows 10/11 devices managed by Intune. The script needs to run with system context and report its execution status. Which Intune feature should the administrator use to deploy this script?Manage identity and compliance (10-15%)
- 12.A company policy requires that all corporate-owned Windows 11 devices automatically enroll into Microsoft Intune when a user signs in for the first time with their Azure AD account. You need to configure this automatic enrollment. Which method should you implement?Manage identity and compliance (10-15%)
- 13.A company policy states that all highly confidential emails sent from Exchange Online must be encrypted and prevent forwarding. The administrator has already created a sensitivity label named 'Highly Confidential' with the appropriate encryption and content marking settings. Which additional step is required to enforce the 'prevent forwarding' restriction when users apply this label?Manage identity and compliance (10-15%)
- 14.A company is implementing a new policy to restrict access to Microsoft 365 services. Users should only be able to access Exchange Online and SharePoint Online from devices that are either compliant or Hybrid Azure AD joined. Access from any other device state should be blocked. Which type of Conditional Access policy condition should you configure to enforce this requirement?Manage identity and compliance (10-15%)
- 15.An organization uses Microsoft Intune to manage its Windows 11 devices. A new security baseline has been released by Microsoft, and the security team wants to apply it to all corporate devices. Which Intune feature should the administrator use to quickly deploy and manage these recommended security settings?Manage identity and compliance (10-15%)
- 16.A company policy dictates that all corporate-owned Windows 11 devices must have BitLocker encryption enabled and require a PIN at startup. You need to configure Microsoft Intune to enforce this policy. Which type of policy should you use?Manage identity and compliance (10-15%)
- 17.A Microsoft 365 Endpoint Administrator is configuring a new sensitivity label in Microsoft Purview. The label needs to automatically apply to documents that contain credit card numbers. Which automatic labeling method should the administrator configure?Manage identity and compliance (10-15%)
- 18.A global manufacturing company needs to manage mobile devices (iOS and Android) for its frontline workers. These devices are corporate-owned and will be used exclusively for work-related tasks, with minimal user interaction required for setup. The company wants to ensure strict control over app installations and device settings. Which Intune enrollment method would be most suitable for these devices?Manage identity and compliance (10-15%)
- 19.A company has a hybrid Azure AD environment. All user accounts are synchronized from on-premises Active Directory. You need to ensure that when a user's account is deleted from the on-premises Active Directory, their corresponding Azure AD account is also automatically deleted, and their enrolled devices are deprovisioned from Intune. Which component is responsible for synchronizing these deletions from on-premises to Azure AD?Manage identity and compliance (10-15%)
- 20.An administrator is configuring a new Conditional Access policy to require multi-factor authentication (MFA) for all users accessing SharePoint Online from outside the corporate network. After creating the policy, the administrator tests it with their own account, which is a global administrator. The policy does not trigger MFA. What is the most likely reason for this behavior?Manage identity and compliance (10-15%)
- 21.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices have a specific application, 'ContosoApp.exe', installed and running. If the application is not present or not running, the device should be marked as non-compliant. Which Intune feature should the administrator use to achieve this?Manage identity and compliance (10-15%)
- 22.A user reports that their corporate-owned Android device, enrolled in Intune as a Fully Managed device, is not receiving company-specific applications deployed through Intune. You verify that the apps are assigned to the correct user group and the device is compliant. Which critical component on the Android device is responsible for receiving and installing these applications and should be checked first?Manage identity and compliance (10-15%)
- 23.An organization uses Microsoft Intune to manage its corporate-owned iOS devices. A new security policy requires that all iOS devices must have a passcode set, and this passcode must meet a minimum complexity requirement. Additionally, if a device is found to be non-compliant with this passcode policy, it should automatically be marked as non-compliant in Intune. Which Intune configuration should the administrator use to implement this policy?Manage identity and compliance (10-15%)
- 24.A company uses Microsoft Intune to manage its devices. A new compliance policy states that all Windows 11 devices must have BitLocker enabled and a specific Windows Defender Antivirus configuration. You create a new device compliance policy in Intune for Windows 11. To ensure this policy is enforced, what is the next crucial step after creating the policy?Manage identity and compliance (10-15%)
- 25.A company policy dictates that all unmanaged devices accessing Microsoft 365 services must use a compliant app for email and document viewing. You need to implement this policy to ensure that devices not enrolled in Intune still adhere to security standards. Which Microsoft Intune feature should you configure?Manage identity and compliance (10-15%)
- 26.A global company needs to ensure that all user devices accessing corporate resources are registered with Azure Active Directory (Azure AD) and are compliant with company policies. This includes personal mobile devices (BYOD) and corporate laptops. Which Azure AD device state fully satisfies both requirements?Manage identity and compliance (10-15%)
- 27.A Microsoft 365 Endpoint Administrator is configuring a new set of shared corporate-owned Android Enterprise devices that will be used as digital signage in lobbies. These devices must only run a single specific application in full-screen mode, and users should not be able to access any other apps or device settings. Which Android Enterprise deployment scenario should the administrator choose?Manage devices and apps (55-60%)
- 28.A Microsoft 365 Endpoint Administrator needs to deploy a custom application to a group of macOS devices. The application is provided as a .pkg file and does not require any pre- or post-installation scripts. The administrator wants to ensure that the application is installed silently and automatically on targeted devices. Which Intune application type should be used?Manage devices and apps (55-60%)
- 29.A Microsoft 365 Endpoint Administrator needs to deploy a custom configuration profile to a group of Windows 11 devices using Microsoft Intune. This configuration is not available through standard Intune settings templates. The administrator has identified the correct OMA-URI string, data type, and value for the setting. Which profile type should the administrator create in Intune?Manage devices and apps (55-60%)
- 30.A Microsoft 365 Endpoint Administrator is configuring Microsoft Intune for a new set of corporate-owned Android Enterprise devices. These devices will be used in a retail store for point-of-sale (POS) transactions and should only run the POS application, with no access to other apps or device settings. Which Android Enterprise deployment scenario should the administrator choose?Manage devices and apps (55-60%)
- 31.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices automatically enroll into Microsoft Intune when users sign in with their organizational accounts for the first time. Which configuration in Azure Active Directory (Azure AD) should be verified or configured?Manage devices and apps (55-60%)
- 32.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned iOS devices have a standardized set of security and functional configurations, such as passcode requirements, device feature restrictions (e.g., camera use), and Wi-Fi profiles. Which Intune profile type is primarily used for these general device settings?Manage devices and apps (55-60%)
- 33.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices receive quality updates from Microsoft and defer them for a maximum of 21 days from their release. Which value should be configured for 'Quality update deferral period (days)' in the Windows Update ring?Manage devices and apps (55-60%)
- 34.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices automatically enroll into Microsoft Intune when they are joined to Azure Active Directory. Which setting in Azure Active Directory (now Microsoft Entra ID) should be configured?Manage devices and apps (55-60%)
- 35.A Microsoft 365 Endpoint Administrator is configuring a new set of corporate-owned iOS devices. The organization requires that users are prevented from installing apps from the public App Store to ensure only approved applications are used. Which Intune configuration profile setting should the administrator use to achieve this?Manage devices and apps (55-60%)
- 36.A company uses Microsoft Intune to manage its corporate-owned iOS devices. Due to compliance requirements, all devices must enforce a minimum passcode length of 6 characters and automatically lock after 5 minutes of inactivity. Additionally, users must be prevented from installing apps from the App Store. Which Intune policy type should the Microsoft 365 Endpoint Administrator use to configure these settings?Manage devices and apps (55-60%)
- 37.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices automatically install quality updates as soon as possible after release, but with a maximum deferral of 3 days. Feature updates should be deferred for 90 days. Which Intune policy type should be configured to achieve this, and where is the quality update deferral setting located?Manage devices and apps (55-60%)
- 38.A Microsoft 365 Endpoint Administrator needs to deploy a custom script to all corporate-owned Windows 11 devices to optimize system performance. The script runs a series of PowerShell commands. The administrator wants to ensure the script runs only once per device and reports its execution status back to Intune. Which Intune feature should be used?Manage devices and apps (55-60%)
- 39.A Microsoft 365 Endpoint Administrator needs to deploy a custom configuration to a subset of Windows 11 devices. This configuration involves setting a registry key that is not exposed through standard Intune settings or the Settings Catalog. The administrator has created a PowerShell script to achieve this. How should the administrator deploy this script to the target devices via Intune?Manage devices and apps (55-60%)
- 40.A Microsoft 365 Endpoint Administrator needs to deploy a security baseline to all corporate-owned Windows 11 devices. The baseline must align with industry best practices for security and should be easily updated as new recommendations become available. Which Intune feature should be used?Manage devices and apps (55-60%)
- 41.A Microsoft 365 Endpoint Administrator needs to deploy a custom configuration to a specific registry key on all corporate-owned Windows 11 devices. This setting is not directly available through standard Intune device configuration profiles or ADMX templates. The administrator has the OMA-URI string and the desired value for the setting. Which Intune policy type should be used?Manage devices and apps (55-60%)
- 42.A Microsoft 365 Endpoint Administrator needs to deploy a critical security application to all corporate-owned Windows 11 devices. This application requires specific pre-installation checks, custom installation parameters, and post-installation scripts for configuration. Which Intune app deployment type is best suited for this scenario?Manage devices and apps (55-60%)
- 43.A company is managing Windows 11 devices with Microsoft Intune. They want to ensure that all devices have a specific set of security configurations enforced that align with industry best practices, such as disabling SMBv1 and enabling firewall rules, without having to manually configure each setting individually. Which Intune feature is designed for this purpose?Manage devices and apps (55-60%)
- 44.A Microsoft 365 Endpoint Administrator needs to configure a Windows Update ring for corporate-owned Windows 11 devices. The policy requires that Feature Updates be deferred for 90 days and Quality Updates for 7 days. Additionally, a deadline of 3 days should be set for Quality Updates to be installed after their deferral period ends, with a grace period of 2 days. What is the latest date a Quality Update released on May 1, 2024, would be installed on a device managed by this policy?Manage devices and apps (55-60%)
- 45.A Microsoft 365 Endpoint Administrator is configuring Microsoft Intune for a new set of corporate-owned Android Enterprise devices. These devices will be used by field technicians and should have a highly restricted, single-purpose experience, only allowing access to a few pre-approved applications. Users should not be able to access device settings or install other applications. Which Android Enterprise management scenario best fits these requirements?Manage devices and apps (55-60%)
- 46.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices automatically install quality updates as soon as possible, but only after they have been thoroughly tested by a pilot group. The pilot group should receive updates 3 days after release, and the remaining production devices should receive updates 10 days after the pilot group. All devices must have a grace period of 2 days before a mandatory restart and will restart automatically outside of active hours. What is the minimum 'Quality update deferral period' that should be configured for the production device update ring?Manage devices and apps (55-60%)
- 47.A company is piloting Microsoft Intune for managing its Android Enterprise devices. They need to deploy a critical line-of-business (LOB) application that is not available in the Google Play Store to all corporate-owned devices. The application must be installed automatically and silently. Which deployment method should you use?Manage devices and apps (55-60%)
- 48.An administrator needs to deploy a custom PowerShell script to perform a specific configuration task on Windows 11 devices managed by Microsoft Intune. The script should run automatically in the system context and report its execution status back to Intune. Which Intune feature is best suited for this requirement?Manage devices and apps (55-60%)
- 49.A company is migrating its device management from on-premises Active Directory Group Policy Objects (GPOs) to Microsoft Intune. They have a critical GPO that configures a specific security setting for Windows Firewall that is not available in the Intune Settings Catalog or as a standard device restriction. The GPO is based on a custom ADMX file. How should the administrator import and deploy this setting to Windows 11 devices using Intune?Manage devices and apps (55-60%)
- 50.A Microsoft 365 Endpoint Administrator is managing a fleet of corporate-owned Windows 11 devices. The security team has mandated that no users should be able to uninstall applications from the 'Apps & features' section in Windows Settings. Additionally, access to the command prompt and PowerShell must be blocked. Which Intune configuration profile type and specific settings should be used?Manage devices and apps (55-60%)