Microsoft 365 Endpoint Administrator practice questions

205 free questions with answers and explanations.

Practice test
  1. 51.A Microsoft 365 Endpoint Administrator is configuring Microsoft Intune to manage corporate-owned Windows 11 devices. The organization requires that all devices automatically install critical and security updates as soon as they are available, but feature updates should be deferred for 30 days to allow for compatibility testing. You need to configure an update policy to meet these requirements. Which Intune configuration should you use?Manage devices and apps (55-60%)
  2. 52.A Microsoft 365 Endpoint Administrator is managing Windows 11 devices with Microsoft Intune. A new security policy dictates that all devices must have BitLocker enabled, and their recovery keys must be escrowed to Azure Active Directory for administrative access and recovery purposes. Which Intune policy setting should be configured to ensure BitLocker recovery keys are stored in Azure AD?Manage devices and apps (55-60%)
  3. 53.A company policy dictates that all corporate-owned Windows 11 devices must have a specific set of required applications installed (e.g., Microsoft Office, an internal LOB app, and a VPN client). If a user uninstalls one of these applications, Intune must automatically reinstall it. Which assignment type should be used when deploying these applications in Intune?Manage devices and apps (55-60%)
  4. 54.A Microsoft 365 Endpoint Administrator needs to deploy a custom script to all corporate-owned Windows 11 devices to optimize system performance. The script runs a series of PowerShell commands. The administrator wants to ensure the script runs only once per device and reports its execution status back to Intune. Which Intune feature should be used?Manage devices and apps (55-60%)
  5. 55.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices receive quality updates from Microsoft and defer them for a maximum of 21 days from their release. Which value should be configured for 'Quality update deferral period (days)' in the Windows Update ring?Manage devices and apps (55-60%)
  6. 56.An administrator needs to deploy a custom PowerShell script to perform a specific configuration task on Windows 11 devices managed by Microsoft Intune. The script should run automatically in the system context and report its execution status back to Intune. Which Intune feature is best suited for this requirement?Manage devices and apps (55-60%)
  7. 57.A Microsoft 365 Endpoint Administrator is managing a fleet of corporate-owned Windows 11 devices. The company policy states that all Windows quality updates must be deferred by 7 days after their release, and feature updates must be deferred by 60 days. Which specific Intune setting in an update ring policy controls the delay for quality updates?Manage devices and apps (55-60%)
  8. 58.A Microsoft 365 Endpoint Administrator is configuring a new set of corporate-owned iOS devices. The organization requires that users are prevented from installing apps from the public App Store to ensure only approved applications are used. Which Intune configuration profile setting should the administrator use to achieve this?Manage devices and apps (55-60%)
  9. 59.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices receive quality updates within 7 days of release, but feature updates should be deferred by 60 days. Devices must restart automatically outside of active hours to apply updates. Which Intune policy configuration should the administrator use?Manage devices and apps (55-60%)
  10. 60.A Microsoft 365 Endpoint Administrator needs to deploy a critical Line-of-Business (LOB) application to all corporate-owned macOS devices. The application is packaged as a .pkg file. Which application type should the administrator select in Microsoft Intune to deploy this application?Manage devices and apps (55-60%)
  11. 61.A Microsoft 365 Endpoint Administrator is configuring Microsoft Intune to manage corporate-owned Android Enterprise devices. The goal is to restrict users from installing apps from unknown sources and prevent the use of developer options. Which type of Intune policy should be used to achieve this?Manage devices and apps (55-60%)
  12. 62.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices automatically enroll into Microsoft Intune when users sign in with their organizational accounts for the first time. Which configuration in Azure Active Directory (Azure AD) should be verified or configured?Manage devices and apps (55-60%)
  13. 63.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices have BitLocker enabled, with recovery keys automatically escrowed to Azure Active Directory. Users should not be prompted for BitLocker setup. Which Intune policy type should be configured?Manage devices and apps (55-60%)
  14. 64.A Microsoft 365 Endpoint Administrator is managing a fleet of corporate-owned Android Enterprise devices set up in 'fully managed' mode. The organization requires that users are prevented from changing system settings, such as Wi-Fi, Bluetooth, or screen timeout, to maintain a consistent and secure environment. Which Intune configuration profile setting should the administrator use?Manage devices and apps (55-60%)
  15. 65.A Microsoft 365 Endpoint Administrator is configuring a new set of shared corporate-owned Android Enterprise dedicated devices (kiosk mode). These devices will be used by multiple users in shifts and should only allow access to a single, specific application. Users should not be able to access device settings, notifications, or the home screen. Which Android Enterprise management scenario and Intune profile type should be chosen?Manage devices and apps (55-60%)
  16. 66.A Microsoft 365 Endpoint Administrator is configuring Microsoft Intune for a new set of corporate-owned Android Enterprise devices. These devices will be used by field technicians and should have a highly restricted, single-purpose experience, only allowing access to a few pre-approved applications. Users should not be able to access device settings or install other applications. Which Android Enterprise management scenario best fits these requirements?Manage devices and apps (55-60%)
  17. 67.A Microsoft 365 Endpoint Administrator is managing a fleet of corporate-owned Windows 11 devices. The company policy dictates that all drivers and firmware updates must be thoroughly tested before being deployed to production devices. However, critical security updates should be applied as soon as possible. Which Intune feature provides the most granular control to manage both driver/firmware updates and critical security updates separately?Manage devices and apps (55-60%)
  18. 68.A technician needs to configure a Wi-Fi profile for corporate-owned iOS devices using Microsoft Intune. The profile must automatically connect to the 'Corporate_Secure_WiFi' network, which uses WPA2 Enterprise with 802.1X authentication (EAP-TLS). The devices should use certificates for authentication. Which Intune configuration profile type and authentication method should the technician configure?Manage devices and apps (55-60%)
  19. 69.A Microsoft 365 Endpoint Administrator needs to deploy a custom application to macOS devices. The application is packaged as a standard .DMG file. The administrator wants to use Microsoft Intune to deploy this application. Which application type should the administrator select in Intune to deploy the .DMG file?Manage devices and apps (55-60%)
  20. 70.A Microsoft 365 Endpoint Administrator is managing Windows 11 devices with Microsoft Intune. To ensure data protection, BitLocker is enabled on all devices, and the recovery keys are required to be stored securely in Azure Active Directory. During an audit, it was discovered that some devices are not escrowing their keys. Which specific location in Azure AD should the administrator check to verify if a device's BitLocker recovery key has been successfully escrowed?Manage devices and apps (55-60%)
  21. 71.A Microsoft 365 Endpoint Administrator needs to deploy a security baseline to all corporate-owned Windows 11 devices. The organization has specific compliance requirements that align with industry best practices for Windows security. The administrator wants to use a standardized, pre-configured set of security settings provided by Microsoft. Which Intune feature should the administrator use?Manage devices and apps (55-60%)
  22. 72.A Microsoft 365 Endpoint Administrator is managing a fleet of corporate-owned Windows 11 devices. The security team has mandated that no users should be able to uninstall applications from the 'Apps & features' section in Windows Settings. Additionally, access to the command prompt and PowerShell must be blocked. Which Intune configuration profile type and specific settings should be used?Manage devices and apps (55-60%)
  23. 73.A company is migrating its device management from on-premises Active Directory Group Policy Objects (GPOs) to Microsoft Intune. They have a critical GPO that configures a specific security setting for Windows Firewall that is not available in the Intune Settings Catalog or as a standard device restriction. The GPO is based on a custom ADMX file. How should the administrator import and deploy this setting to Windows 11 devices using Intune?Manage devices and apps (55-60%)
  24. 74.A Microsoft 365 Endpoint Administrator needs to deploy a custom PowerShell script to all corporate-owned Windows 11 devices to optimize system performance by clearing temporary files. The script should run with administrator privileges and report its execution status back to Intune. Which Intune feature should be used for this deployment?Manage devices and apps (55-60%)
  25. 75.A Microsoft 365 Endpoint Administrator needs to deploy a custom configuration profile to a group of Windows 11 devices using Microsoft Intune. This configuration is not available through standard Intune settings templates. The administrator has identified the correct OMA-URI string, data type, and value for the setting. Which profile type should the administrator create in Intune?Manage devices and apps (55-60%)
  26. 76.A company is piloting Microsoft Intune for managing its Android Enterprise devices. They need to deploy a critical line-of-business (LOB) application that is not available in the Google Play Store to all corporate-owned devices. The application must be installed automatically and silently. Which deployment method should you use?Manage devices and apps (55-60%)
  27. 77.A company policy requires that all corporate-owned Windows 11 devices automatically install available quality updates within 7 days of their release. Users should be able to pause updates for a maximum of 3 days. Which Intune policy setting should be configured to meet these requirements?Manage devices and apps (55-60%)
  28. 78.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned iOS devices enforce a passcode policy that requires a minimum length of 6 characters and auto-locks after 5 minutes of inactivity. Users should also be prevented from using simple passcodes. Which Intune policy type should be used?Manage devices and apps (55-60%)
  29. 79.A Microsoft 365 Endpoint Administrator needs to configure a custom setting on Windows 11 devices that is not available in any of Intune's built-in configuration profiles or templates. The setting is documented as a Configuration Service Provider (CSP) URI. Which Intune profile type should be used for this purpose?Manage devices and apps (55-60%)
  30. 80.A Microsoft 365 Endpoint Administrator needs to deploy a custom security agent to all corporate-owned Windows 11 devices using Microsoft Intune. The agent requires specific command-line arguments during installation and needs to check for a registry key to confirm successful deployment. Which application type in Intune should be used?Manage devices and apps (55-60%)
  31. 81.A Microsoft 365 Endpoint Administrator is managing corporate-owned Windows 11 devices with Microsoft Intune. To enhance security, a policy needs to be implemented to ensure that all devices have BitLocker enabled, and their recovery keys are automatically backed up to Azure Active Directory. Which Intune policy type is best suited for this requirement?Manage devices and apps (55-60%)
  32. 82.A Microsoft 365 Endpoint Administrator needs to deploy a critical Line-of-Business (LOB) application to all corporate-owned Windows 11 devices. The application is packaged as an MSI file. Users should not be able to remove this application, and it must be installed automatically without user intervention. Which assignment type should be used when deploying the LOB app in Intune?Manage devices and apps (55-60%)
  33. 83.A Microsoft 365 Endpoint Administrator needs to deploy a critical security application to all Windows 11 devices managed by Intune. The application is packaged as a Win32 app and requires specific installation and uninstallation commands. Which application deployment type in Intune should the administrator use to ensure the application is installed correctly with its custom commands?Manage devices and apps (55-60%)
  34. 84.A Microsoft 365 Endpoint Administrator needs to deploy a critical Line-of-Business (LOB) application to all corporate-owned iOS devices. The application is a .IPA file and is not available in the Apple App Store. Which application deployment method should be used in Microsoft Intune?Manage devices and apps (55-60%)
  35. 85.A Microsoft 365 Endpoint Administrator is managing Windows 11 devices with Microsoft Intune. The organization has a strict policy requiring that all corporate data on devices, both at rest and in transit, must be encrypted. For data at rest, BitLocker is already configured via Intune. For data in transit, a VPN solution is in place. You need to verify the BitLocker recovery key escrow status for a specific device. Where would you find the BitLocker recovery key for an Intune-managed Windows 11 device?Manage devices and apps (55-60%)
  36. 86.A Microsoft 365 Endpoint Administrator needs to deploy a custom security agent to all corporate-owned Windows 11 devices. This agent requires a complex installation script that runs multiple commands, checks for prerequisites, and logs its progress. The agent is packaged as an .intunewin file. Which Intune app deployment type is most suitable for this scenario?Manage devices and apps (55-60%)
  37. 87.A company is using Microsoft Intune to manage its Windows 11 devices. The IT department needs to deploy a custom security baseline that includes settings not found in Microsoft's default security baselines or the Settings Catalog. These settings are derived from a specific industry compliance standard. Which Intune configuration profile type should be used to deploy these unique settings?Manage devices and apps (55-60%)
  38. 88.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned macOS devices have a specific Wi-Fi profile deployed. This profile uses WPA2 Enterprise security with 802.1X authentication and requires a user certificate for EAP-TLS. Which Intune configuration profile type for macOS should be used to deploy this Wi-Fi profile?Manage devices and apps (55-60%)
  39. 89.A Microsoft 365 Endpoint Administrator is deploying a new corporate application to iOS devices. The application is an in-house developed .ipa file and needs to be deployed directly to all corporate-owned iPads. What type of app should be selected in Microsoft Intune for this deployment?Manage devices and apps (55-60%)
  40. 90.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned iOS devices have a specific Wi-Fi network profile pushed to them. This network uses WPA2 Enterprise with 802.1X authentication, requiring a username and password for connection. Users should not be able to modify the network settings once configured. Which Intune configuration profile type should the administrator use?Manage devices and apps (55-60%)
  41. 91.A Microsoft 365 Endpoint Administrator is configuring a new set of shared corporate-owned Android Enterprise dedicated devices for frontline workers. These devices will be used exclusively for a single inventory application and must not allow access to other apps or device settings. Which enrollment method and configuration type should be used?Manage devices and apps (55-60%)
  42. 92.A company uses Microsoft Intune for device management. They want to ensure that all corporate-owned iOS devices receive critical security updates immediately upon release. Which Intune feature allows administrators to control and deploy iOS/iPadOS updates to managed devices?Manage devices and apps (55-60%)
  43. 93.A global organization uses Microsoft Intune to manage its Windows devices. Due to regulatory requirements, devices in the European region must receive Windows feature updates only after a 60-day deferral period to allow for compatibility testing. Devices in other regions should receive updates after a 30-day deferral. How should an administrator configure this in Intune?Manage devices and apps (55-60%)
  44. 94.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned macOS devices have a specific Wi-Fi network configured automatically with WPA2 Enterprise (EAP-TLS) authentication. The Wi-Fi network requires a client certificate for authentication. Which Intune profile type should be used?Manage devices and apps (55-60%)
  45. 95.A Microsoft 365 Endpoint Administrator needs to deploy a custom configuration profile to a specific group of Windows 11 devices. This configuration requires setting a custom registry value that is not directly available through standard Intune device configuration templates. Which profile type should the administrator choose, and what is its underlying mechanism for this scenario?Manage devices and apps (55-60%)
  46. 96.A Microsoft 365 Endpoint Administrator needs to deploy a complex, multi-step application installation and configuration to a group of Windows 11 devices using Microsoft Intune. This involves running several scripts and installing multiple dependencies before the main application can be installed. Which Intune application deployment type is best suited for this scenario?Manage devices and apps (55-60%)
  47. 97.A Microsoft 365 Endpoint Administrator is managing corporate-owned Windows 11 devices using Microsoft Intune. The organization requires that BitLocker encryption keys for these devices are automatically backed up to Azure Active Directory to ensure recovery in case of data loss or forgotten passwords. Which Intune policy setting enables this functionality?Manage devices and apps (55-60%)
  48. 98.A Microsoft 365 Endpoint Administrator needs to deploy a security baseline to all Windows 11 devices to enforce a standardized set of security configurations recommended by Microsoft. The baseline should cover settings like password policies, firewall rules, and Defender configurations. Which Intune feature should the administrator use?Manage devices and apps (55-60%)
  49. 99.A Microsoft 365 Endpoint Administrator needs to deploy a custom configuration profile to a specific group of Windows 11 devices. This configuration requires setting a registry key value that is not directly exposed in any of Intune's built-in templates or settings catalogs. Which Intune profile type should be used to achieve this?Manage devices and apps (55-60%)
  50. 100.A Microsoft 365 Endpoint Administrator is configuring a new set of corporate-owned iOS devices. The company policy requires that all applications installed on these devices must be reviewed and approved by IT. Users should not be able to install apps from the public Apple App Store directly. Which Intune policy setting should be configured?Manage devices and apps (55-60%)