Microsoft 365 Endpoint Administrator practice questions
205 free questions with answers and explanations.
- 101.A Microsoft 365 Endpoint Administrator is configuring a new set of corporate-owned iOS devices. The company policy requires that all applications installed on these devices must be reviewed and approved by IT. Users should not be able to install apps from the public Apple App Store directly. Which Intune policy setting should be configured?Manage devices and apps (55-60%)
- 102.A Microsoft 365 Endpoint Administrator needs to deploy a custom PowerShell script to all corporate-owned Windows 11 devices. The script will configure a specific application setting that requires administrative privileges to run successfully. The script should run once upon deployment and report its status back to Intune. Which method for deploying PowerShell scripts in Intune should be used?Manage devices and apps (55-60%)
- 103.A Microsoft 365 Endpoint Administrator is managing Windows 11 devices with Microsoft Intune. The company requires a specific set of security configurations, including firewall rules, Windows Defender settings, and BitLocker encryption, to be consistently applied across all devices. The administrator wants to ensure that these settings are applied according to industry best practices and are automatically updated by Microsoft. Which Intune feature should be used?Manage devices and apps (55-60%)
- 104.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices automatically enroll into Microsoft Intune when users sign in for the first time with their organizational accounts. The devices are currently joined to on-premises Active Directory. Which enrollment method should be configured?Manage devices and apps (55-60%)
- 105.A Microsoft 365 Endpoint Administrator wants to prevent users on corporate-owned macOS devices from installing applications from any source other than the Mac App Store. This is a strict security requirement. Which Intune policy setting should be configured?Manage devices and apps (55-60%)
- 106.An administrator needs to deploy a critical Line-of-Business (LOB) application to all corporate-owned iOS devices. The application is an .ipa file and must be installed on all devices without user interaction, making it a mandatory installation. Which application assignment type in Intune should the administrator use?Manage devices and apps (55-60%)
- 107.A Microsoft 365 Endpoint Administrator needs to deploy a critical Line-of-Business (LOB) application to all corporate-owned iOS devices. The application is developed internally and is packaged as an .ipa file. The administrator wants to ensure that the app is automatically installed on devices without user interaction and that updates are also pushed automatically. Which Intune app assignment type should be used?Manage devices and apps (55-60%)
- 108.A technician is configuring Microsoft Intune for a new set of corporate-owned Android Enterprise devices. The company policy requires that all applications installed on these devices must be approved by the IT department and come from a controlled source. Users should not be able to install apps directly from the public Google Play Store. Which enrollment type should the technician use to ensure this level of control?Manage devices and apps (55-60%)
- 109.A Microsoft 365 Endpoint Administrator needs to deploy a custom application to a group of macOS devices. The application is packaged as a .pkg file and requires administrative privileges to install. The administrator wants to ensure that the installation process is silent and that the application is installed in the /Applications folder. Which Intune app deployment method for macOS should be used?Manage devices and apps (55-60%)
- 110.An organization uses Microsoft Intune to manage its macOS devices. A critical internal application, packaged as a .PKG file, needs to be deployed to all corporate macOS machines. This application is not available in the Apple App Store. Users must not be able to remove this application. Which Intune app deployment method and assignment type should be used?Manage devices and apps (55-60%)
- 111.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices automatically enroll into Microsoft Intune when they are joined to Azure Active Directory. Which configuration should the administrator implement?Manage devices and apps (55-60%)
- 112.A company uses Microsoft Intune to manage its Windows 11 devices. You need to ensure that all corporate-owned devices can only install applications from the Microsoft Store and other approved sources, preventing users from installing unapproved software. Which Intune configuration profile setting should you configure?Manage devices and apps (55-60%)
- 113.A Microsoft 365 Endpoint Administrator needs to deploy a critical Line-of-Business (LOB) application to all corporate-owned Android Enterprise fully managed devices. The application is packaged as an .APK file. Users should not be able to uninstall this application. Which assignment type should the administrator use when deploying the application in Microsoft Intune?Manage devices and apps (55-60%)
- 114.A Microsoft 365 Endpoint Administrator needs to deploy a critical Line-of-Business (LOB) application to all corporate-owned Windows 11 devices. The application installer is a standard .msi file and must be installed silently without user interaction. Which application type should be used in Microsoft Intune to achieve this?Manage devices and apps (55-60%)
- 115.A Microsoft 365 Endpoint Administrator is managing a fleet of corporate-owned Android Enterprise fully managed devices. A new security policy dictates that all devices must have a minimum screen lock password length of 6 characters and automatically lock after 5 minutes of inactivity. Which Intune policy type should be used to enforce these settings?Manage devices and apps (55-60%)
- 116.A Microsoft 365 Endpoint Administrator needs to configure a custom setting on Windows 11 devices that is not available through standard Intune device configuration profiles. The setting requires modifying a specific registry key value. Which Intune profile type should be used?Manage devices and apps (55-60%)
- 117.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices have the latest recommended security settings applied based on industry best practices. These settings should be automatically configured and monitored for compliance. Which Intune feature should be used?Manage devices and apps (55-60%)
- 118.A Microsoft 365 Endpoint Administrator needs to create a Wi-Fi profile for corporate-owned iOS devices. The profile must ensure secure authentication using client certificates and encrypt all traffic. The network infrastructure uses WPA2-Enterprise with EAP-TLS. Which security type should be selected when configuring the Wi-Fi profile in Microsoft Intune?Manage devices and apps (55-60%)
- 119.A Microsoft 365 Endpoint Administrator needs to configure a Wi-Fi profile for corporate-owned iOS devices. The profile must require users to authenticate with their Azure Active Directory credentials and ensure that communication is secured using TLS. Which authentication method should be selected in the Wi-Fi profile?Manage devices and apps (55-60%)
- 120.A company is implementing Microsoft Intune to manage its Windows 11 devices. The security team requires that all managed devices automatically encrypt their hard drives using BitLocker as soon as they enroll, without user interaction. Which Intune policy setting should you configure to meet this requirement?Manage devices and apps (55-60%)
- 121.A company is using Microsoft Intune to manage its Android Enterprise corporate-owned devices. They need to ensure that specific applications are always present and up-to-date on all devices, without user interaction. These applications are available in the Managed Google Play Store. Which application assignment type should the administrator use to achieve this?Manage devices and apps (55-60%)
- 122.A company is migrating its device management from on-premises Active Directory Group Policy to Microsoft Intune. They have a custom ADMX template for managing a legacy application's settings. To apply these settings to Windows 11 devices enrolled in Intune, what is the most efficient method?Manage devices and apps (55-60%)
- 123.A Microsoft 365 Endpoint Administrator is managing a fleet of corporate-owned Windows 11 devices. The company policy requires that all devices must have a specific set of security configurations applied, including Defender antivirus settings, firewall rules, and attack surface reduction rules. These settings need to be consistently applied and monitored for compliance. Which Intune feature is designed to deploy and manage these types of security settings?Manage devices and apps (55-60%)
- 124.A Microsoft 365 Endpoint Administrator needs to deploy a critical Line-of-Business (LOB) application to all corporate-owned iOS devices. This application is internally developed and is provided as an .ipa file. The application must be automatically installed on all targeted devices without user interaction. Which Intune app deployment type should be used for this scenario?Manage devices and apps (55-60%)
- 125.A company is using Microsoft Intune to manage its Windows 11 devices. The IT department needs to deploy a specific application that requires administrative privileges for installation and is packaged as an MSI file. The application must be installed silently on all corporate-owned devices. Which application deployment type in Intune should you choose?Manage devices and apps (55-60%)
- 126.A company is using Microsoft Intune to manage its macOS devices. They want to prevent users from installing applications from outside the Mac App Store to enhance security. Which Intune policy setting should be configured to achieve this?Manage devices and apps (55-60%)
- 127.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices automatically enroll into Microsoft Intune during the Out-of-Box Experience (OOBE) without requiring manual intervention from users. The devices are purchased directly from a hardware vendor. Which pre-provisioning technology should be leveraged?Manage devices and apps (55-60%)
- 128.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices automatically install approved drivers and firmware updates. These updates should be deployed alongside regular quality updates. Which Intune feature allows for the management and deployment of driver and firmware updates?Manage devices and apps (55-60%)
- 129.A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices are always encrypted with BitLocker and that the recovery keys are automatically backed up to Azure Active Directory (now Microsoft Entra ID). The administrator also needs to enforce a specific encryption strength (AES 256-bit). Which Intune Endpoint Security policy type should be configured?Manage devices and apps (55-60%)
- 130.A company is using Microsoft Intune to manage its macOS devices. They need to ensure that all macOS devices have a specific Wi-Fi profile configured with WPA2 Enterprise security, including a pre-shared key, and are set to automatically connect. Which Intune profile type should be used to deploy this Wi-Fi configuration?Manage devices and apps (55-60%)
- 131.A Microsoft 365 Endpoint Administrator is configuring Microsoft Intune to manage corporate-owned Windows 11 devices. The security team requires that all devices automatically install Windows quality updates within 5 days of release and feature updates within 30 days of release. They also want to ensure that devices are rebooted outside of active hours if an update requires a restart. Which Intune policy component should the administrator configure?Manage devices and apps (55-60%)
- 132.A Microsoft 365 Endpoint Administrator is configuring Microsoft Intune to manage corporate-owned Android Enterprise devices. The administrator needs to ensure that users are prevented from installing apps from unknown sources, but still allows app installation from the Google Play Store. Which Intune device restriction setting should be configured?Manage devices and apps (55-60%)
- 133.A Microsoft 365 Endpoint Administrator is managing a fleet of corporate-owned Windows 11 devices with Microsoft Intune. To enhance security, the administrator needs to ensure that BitLocker encryption keys are automatically escrowed to Azure Active Directory (now Microsoft Entra ID) for recovery purposes. Which Intune profile type should be configured?Manage devices and apps (55-60%)
- 134.A Microsoft 365 Endpoint Administrator needs to deploy a custom PowerShell script to all Windows 11 devices to optimize system performance. The script must run with administrator privileges and report its execution status back to Intune. What is the correct method to deploy this script using Microsoft Intune?Manage devices and apps (55-60%)
- 135.A company uses Microsoft Intune to manage its corporate-owned iOS devices. Due to security concerns, the IT department wants to prevent users from installing applications from any source other than the Apple App Store. Which Intune device restriction setting should be configured?Manage devices and apps (55-60%)
- 136.An organization is migrating 200 Windows 10 devices to Windows 11. They want to perform a 'wipe and load' deployment to ensure a clean installation, but also need to retain user documents, settings, and application data. The IT team plans to use a network share for storing user data during the migration. Which tool is specifically designed to capture and restore user profiles in this scenario?Deploy Windows client (25-30%)
- 137.A technician is troubleshooting a Windows 11 device that is unable to boot. The device displays a 'Critical Process Died' error during startup. The technician suspects a corrupted system file is preventing successful boot. Which command-line utility, accessible from the Windows Recovery Environment (WinRE), should the technician use first to attempt to repair corrupted system files?Deploy Windows client (25-30%)
- 138.An IT administrator is troubleshooting a Windows 11 device that is experiencing frequent blue screen errors, even after attempting system restore points. The administrator suspects corrupted system files are the cause. Which command-line utility should be used to scan for and repair corrupted system files?Deploy Windows client (25-30%)
- 139.A global company needs to deploy Windows 11 to devices in multiple countries. Each country requires a specific language interface, regional settings, and keyboard layout. The company wants to deploy a single, universal Windows 11 image and then configure the language and regional settings dynamically based on the device's location or user's preference during or after deployment. Which component should be integrated into the deployment process to achieve this?Deploy Windows client (25-30%)
- 140.A company with 500 Windows 10 devices plans to migrate to Windows 11. They want to perform an in-place upgrade, but a critical line-of-business application is known to have compatibility issues with Windows 11. The application vendor has not yet released a Windows 11 compatible version. The company needs a solution to allow users to continue running this legacy application seamlessly on their upgraded Windows 11 devices. Which Windows feature provides the best solution for running legacy applications in such a scenario?Deploy Windows client (25-30%)
- 141.An IT administrator is preparing a custom Windows 11 image for deployment. The image needs to include several out-of-box device drivers that are not included in the default Windows 11 installation media. The administrator wants to add these drivers to the offline image before deployment. Which DISM command-line option should be used for this purpose?Deploy Windows client (25-30%)
- 142.A company is migrating 300 Windows 10 devices to Windows 11. They want to minimize network bandwidth consumption during the deployment of the Windows 11 installation files. The devices are spread across several branch offices, each with limited internet connectivity but good local network speeds. Which Windows deployment feature should be configured to achieve this goal?Deploy Windows client (25-30%)
- 143.A small business with 20 Windows 10 Pro devices needs to upgrade to Windows 11 Pro. They want a straightforward, automated upgrade process that requires minimal user interaction and preserves existing user data and applications. The devices are all managed by Microsoft Intune. Which method is most suitable for this upgrade?Deploy Windows client (25-30%)
- 144.A small design firm with 15 Windows 10 Pro workstations needs to upgrade to Windows 11 Pro. They want to retain all user settings, applications, and data. The firm has limited IT staff and prefers a straightforward upgrade process with minimal manual intervention. Which upgrade strategy is most appropriate?Deploy Windows client (25-30%)
- 145.A global organization is deploying Windows 11 to devices in 15 different countries. Each country requires the operating system interface to be displayed in its local language, along with region-specific formats for dates, times, and currency. Which feature should the IT department utilize to efficiently manage these language and regional settings?Deploy Windows client (25-30%)
- 146.A company is planning to deploy Windows 11 to 500 new devices. They want to ensure that all devices are automatically enrolled into Microsoft Intune, pre-configured with company policies, and ready for user login immediately upon delivery, with minimal IT intervention. Which deployment technology should they use?Deploy Windows client (25-30%)
- 147.A global company needs to deploy Windows 11 to devices in multiple countries, each requiring a specific language, region, and keyboard layout during the initial setup. They want to streamline the Out-of-Box Experience (OOBE) for end-users in each region. Which component should be included in the Windows 11 image or configured during deployment to ensure the correct localized experience?Deploy Windows client (25-30%)
- 148.A large enterprise is planning to migrate 5,000 Windows 10 devices to Windows 11. They require a deployment solution that can manage custom images, integrate with existing on-premises infrastructure, and provide robust reporting capabilities. The solution must also support PXE boot for bare-metal deployments and allow for task sequencing to automate complex installation steps. Which deployment tool is best suited for these requirements?Deploy Windows client (25-30%)
- 149.A small business with 25 Windows 10 Pro devices needs to upgrade to Windows 11 Pro. They want a simple, cost-effective method that retains all user data, applications, and settings without requiring reinstallation. The devices are all connected to a local Active Directory domain. Which upgrade method is most appropriate for this scenario?Deploy Windows client (25-30%)
- 150.A company is piloting Windows 11 on 50 devices. They want to ensure that all drivers and firmware are kept up-to-date automatically without requiring manual intervention, but also want to control the timing of these updates. Which Windows Update for Business (WUfB) policy should be configured to manage these types of updates?Deploy Windows client (25-30%)