Step2Study
IT & TechnologyMD-102100% Free

Microsoft 365 Endpoint Administrator

Practice bank
205 Qs
Real exam
40 Qs
Time limit
120 min
Passing
A passing score is 700 or greater.

Exam blueprint

Deploy Windows client (25-30%)
28%
Manage identity and compliance (10-15%)
13%
Manage devices and apps (55-60%)
58%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 270 min · pass 70% · 205 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Microsoft 365 Endpoint Administrator practice test questions

Sample questions from the 205-question bank, with answers and explanations.

All questions
  1. 1. A company policy states that all highly confidential emails sent from Exchange Online must be encrypted and prevent forwarding. The administrator has already created a sensitivity label named 'Highly Confidential' with the appropriate encryption and content marking settings. Which additional step is required to enforce the 'prevent forwarding' restriction when users apply this label?

    Manage identity and compliance (10-15%)

    • A. Ensure the sensitivity label is published to end-users.
    • B. Configure an Exchange mail flow rule (transport rule).
    • C. Enable Azure Information Protection (AIP) Unified Labeling client.
    • D. Configure a Data Loss Prevention (DLP) policy in Microsoft Purview.
    Show answer

    A. Ensure the sensitivity label is published to end-users.

    For users to be able to apply a sensitivity label and for its associated protection settings (like encryption and 'prevent forwarding') to take effect, the label must first be published to them via a label policy.

  2. 2. A Microsoft 365 Endpoint Administrator needs to configure Microsoft Intune to apply specific security settings to devices based on their geographical location. For example, devices accessing corporate data from outside the corporate network should have a stricter set of security policies applied. Which feature in Microsoft Intune should the administrator use to achieve this dynamic policy application?

    Manage identity and compliance (10-15%)

    • A. Device compliance policies
    • B. Conditional Access policies
    • C. Configuration profiles
    • D. Security baselines
    Show answer

    B. Conditional Access policies

    Conditional Access policies are designed to enforce conditions for accessing resources, including location-based restrictions. They work by evaluating signals like user, device, location, and application, then enforcing access decisions.

  3. 3. An organization uses Microsoft Intune to manage its corporate-owned iOS devices. A new security policy requires that all iOS devices must have a passcode set, and this passcode must meet a minimum complexity requirement. Additionally, if a device is found to be non-compliant with this passcode policy, it should automatically be marked as non-compliant in Intune. Which Intune configuration should the administrator use to implement this policy?

    Manage identity and compliance (10-15%)

    • A. Deploy a custom PowerShell script via Intune.
    • B. Create a device restriction profile for iOS.
    • C. Configure a compliance policy for iOS.
    • D. Set up an App Protection Policy (APP) for iOS.
    Show answer

    C. Configure a compliance policy for iOS.

    Compliance policies in Intune are specifically designed to define the conditions that devices must meet to be considered compliant, such as passcode requirements. They also include actions for non-compliance.

  4. 4. An organization uses Microsoft Intune to manage its Windows 11 devices. A new security baseline has been released by Microsoft, and the security team wants to apply it to all corporate devices. Which Intune feature should the administrator use to quickly deploy and manage these recommended security settings?

    Manage identity and compliance (10-15%)

    • A. Device compliance policies
    • B. Security baselines
    • C. Custom OMA-URI settings
    • D. Configuration policies
    Show answer

    B. Security baselines

    Security baselines in Intune are pre-configured groups of Windows settings that help secure devices according to best practices recommended by Microsoft and security teams, making them ideal for deploying new security standards.

  5. 5. A company has a hybrid Azure AD environment. All user accounts are synchronized from on-premises Active Directory. You need to ensure that when a user's account is deleted from the on-premises Active Directory, their corresponding Azure AD account is also automatically deleted, and their enrolled devices are deprovisioned from Intune. Which component is responsible for synchronizing these deletions from on-premises to Azure AD?

    Manage identity and compliance (10-15%)

    • A. Azure AD Connect
    • B. Microsoft Defender for Identity
    • C. Azure AD Connect Health
    • D. Azure AD Domain Services
    Show answer

    A. Azure AD Connect

    Azure AD Connect is the tool responsible for synchronizing identities between on-premises Active Directory and Azure Active Directory. This includes user accounts, groups, and the synchronization of changes like deletions.

  6. 6. A company policy requires that all corporate-owned Windows 11 devices automatically enroll into Microsoft Intune when a user signs in for the first time with their Azure AD account. You need to configure this automatic enrollment. Which method should you implement?

    Manage identity and compliance (10-15%)

    • A. Group Policy Object (GPO) for Hybrid Azure AD Join
    • B. Manual MDM enrollment via Company Portal
    • C. Automatic MDM enrollment via Azure AD Premium
    • D. Bulk enrollment using Windows Autopilot
    Show answer

    C. Automatic MDM enrollment via Azure AD Premium

    Automatic MDM enrollment for Windows devices linked to Azure AD Premium allows devices to automatically enroll in Intune when users sign in with their Azure AD accounts, fulfilling the requirement for corporate-owned devices upon first sign-in.

  7. 7. A user reports that they cannot access a specific SharePoint Online site from their personal laptop, which is not enrolled in Intune. The error message indicates that their device does not meet the organization's compliance requirements. You have already verified that the user's account is enabled and has the correct permissions to the SharePoint site. Which policy type is most likely preventing access?

    Manage identity and compliance (10-15%)

    • A. App protection policy
    • B. Device compliance policy
    • C. Device configuration profile
    • D. Conditional Access policy
    Show answer

    D. Conditional Access policy

    Conditional Access policies are used to enforce access restrictions based on various conditions, including device state (e.g., 'compliant' or 'hybrid Azure AD joined'). An unmanaged personal laptop would likely fail a Conditional Access policy requiring a compliant device.

  8. 8. A Microsoft 365 Endpoint Administrator needs to deploy a custom PowerShell script to all Windows 10/11 devices managed by Intune. The script needs to run with system context and report its execution status. Which Intune feature should the administrator use to deploy this script?

    Manage identity and compliance (10-15%)

    • A. Microsoft Store app deployment
    • B. PowerShell scripts in Intune
    • C. Win32 app deployment
    • D. Device configuration profile (Custom OMA-URI)
    Show answer

    B. PowerShell scripts in Intune

    Intune's dedicated PowerShell scripts feature allows administrators to upload custom PowerShell scripts, assign them to groups, and configure them to run in system or user context, with detailed reporting on execution status. This directly matches the requirements.

  9. 9. A company policy requires that all corporate-owned Android devices must have a work profile for separating corporate and personal data. Additionally, all apps installed within the work profile must be approved by IT. Which Intune enrollment profile should be used for these devices?

    Manage identity and compliance (10-15%)

    • A. Android Enterprise (Fully managed)
    • B. Android device administrator
    • C. Android Enterprise (Dedicated devices)
    • D. Android Enterprise (Work profile)
    Show answer

    D. Android Enterprise (Work profile)

    Android Enterprise (Work profile) enrollment is specifically designed for corporate-owned devices where personal use is allowed but corporate data and apps need to be isolated and managed within a separate work profile.

  10. 10. An administrator is configuring a new Conditional Access policy to require multi-factor authentication (MFA) for all users accessing SharePoint Online from outside the corporate network. After creating the policy, the administrator tests it with their own account, which is a global administrator. The policy does not trigger MFA. What is the most likely reason for this behavior?

    Manage identity and compliance (10-15%)

    • A. MFA is not enabled for the administrator's account.
    • B. Global Administrators are exempt from Conditional Access policies by default.
    • C. The administrator's device is already marked as compliant.
    • D. The policy was not assigned to the correct user group.
    Show answer

    B. Global Administrators are exempt from Conditional Access policies by default.

    By default, Global Administrator accounts are excluded from Conditional Access policies to prevent accidental lockout. This is a crucial safety measure in Azure AD. To test such policies, a non-admin test account or a specific exclusion override is required.

  11. 11. A global manufacturing company needs to manage mobile devices (iOS and Android) for its frontline workers. These devices are corporate-owned and will be used exclusively for work-related tasks, with minimal user interaction required for setup. The company wants to ensure strict control over app installations and device settings. Which Intune enrollment method would be most suitable for these devices?

    Manage identity and compliance (10-15%)

    • A. Automated Device Enrollment (ADE) for iOS or Android Enterprise dedicated devices
    • B. Device enrollment manager (DEM)
    • C. User enrollment
    • D. Bring Your Own Device (BYOD)
    Show answer

    A. Automated Device Enrollment (ADE) for iOS or Android Enterprise dedicated devices

    For corporate-owned devices used for specific work tasks with strict control and minimal user interaction, Automated Device Enrollment (ADE) for iOS/iPadOS or Android Enterprise dedicated devices (formerly Kiosk/COSU) are the most suitable methods. These provide powerful management capabilities and simplify initial setup.

  12. 12. An administrator needs to configure Intune to automatically enroll all new corporate-owned iOS/iPadOS devices without requiring user interaction during the initial setup. The devices are purchased directly from Apple. Which enrollment method should be used?

    Manage identity and compliance (10-15%)

    • A. Apple Configurator
    • B. Direct enrollment
    • C. Apple Business Manager (ABM) / Apple School Manager (ASM)
    • D. Device enrollment manager (DEM)
    Show answer

    C. Apple Business Manager (ABM) / Apple School Manager (ASM)

    Apple Business Manager (ABM) or Apple School Manager (ASM) integration with Intune allows for automated, zero-touch enrollment of corporate-owned iOS/iPadOS devices purchased directly from Apple, ensuring they are enrolled during initial setup.

  13. 13. A global company needs to ensure that all user devices accessing corporate resources are registered with Azure Active Directory (Azure AD) and are compliant with company policies. This includes personal mobile devices (BYOD) and corporate laptops. Which Azure AD device state fully satisfies both requirements?

    Manage identity and compliance (10-15%)

    • A. Hybrid Azure AD joined
    • B. Azure AD registered and Intune compliant
    • C. Azure AD registered
    • D. Azure AD joined
    Show answer

    B. Azure AD registered and Intune compliant

    To ensure devices are registered and compliant, they must first be registered (Azure AD Registered for BYOD, or Joined/Hybrid Joined for corporate) and then explicitly marked as 'compliant' by a management solution like Intune. 'Azure AD registered and Intune compliant' covers both conditions for all device types.

  14. 14. A Microsoft 365 Endpoint Administrator wants to ensure that users can only access corporate resources from specific IP ranges within the company's network. If a user attempts to access resources from outside these IP ranges, access should be blocked. Which Conditional Access condition should be configured?

    Manage identity and compliance (10-15%)

    • A. Sign-in risk
    • B. Locations
    • C. User risk
    • D. Device platforms
    Show answer

    B. Locations

    The 'Locations' condition in Conditional Access policies allows administrators to define trusted IP ranges (named locations) and then either include or exclude them from policy application, directly addressing the need to restrict access based on network location.

  15. 15. A company is implementing a new policy to restrict access to Microsoft 365 services. Users should only be able to access Exchange Online and SharePoint Online from devices that are either compliant or Hybrid Azure AD joined. Access from any other device state should be blocked. Which type of Conditional Access policy condition should you configure to enforce this requirement?

    Manage identity and compliance (10-15%)

    • A. Conditions > Device state
    • B. Conditions > Device platforms
    • C. Users and groups
    • D. Cloud apps or actions
    Show answer

    A. Conditions > Device state

    The 'Device state' condition in Conditional Access policies allows you to specify whether a device must be 'Compliant' or 'Hybrid Azure AD joined' to gain access, directly addressing the requirement to restrict access based on the device's managed status.

  16. 16. A company is implementing a Zero Trust security model. They want to ensure that access to highly sensitive applications is only granted from devices that are considered 'trusted'. For Windows 11 devices, this means they must be Azure AD joined and compliant with Intune policies. Which type of Conditional Access grant control should be configured?

    Manage identity and compliance (10-15%)

    • A. Require multi-factor authentication
    • B. Require Hybrid Azure AD join
    • C. Require device to be marked as compliant
    • D. Require approved client app
    Show answer

    C. Require device to be marked as compliant

    The 'Require device to be marked as compliant' grant control in Conditional Access ensures that only devices that meet the organization's compliance policies (as defined in Intune) are granted access, aligning with the 'trusted device' requirement of Zero Trust.

  17. 17. A company uses Microsoft Intune to manage its devices. A new compliance policy states that all Windows 11 devices must have BitLocker enabled and a specific Windows Defender Antivirus configuration. You create a new device compliance policy in Intune for Windows 11. To ensure this policy is enforced, what is the next crucial step after creating the policy?

    Manage identity and compliance (10-15%)

    • A. Assign the compliance policy to a group of users or devices.
    • B. Configure a Conditional Access policy to block non-compliant devices.
    • C. Create an App protection policy for Windows devices.
    • D. Manually restart all Windows 11 devices to apply the policy.
    Show answer

    A. Assign the compliance policy to a group of users or devices.

    After creating any policy in Intune, it must be assigned to a group of users or devices for it to take effect. Without assignment, the policy exists but is not applied to any endpoints.

  18. 18. A company policy requires that all documents saved to OneDrive for Business from corporate-managed Windows devices must be encrypted. You need to implement a solution that automatically enforces this encryption for new and existing files. Which Microsoft 365 compliance feature should you configure?

    Manage identity and compliance (10-15%)

    • A. Data Loss Prevention (DLP) policies
    • B. Retention policies
    • C. eDiscovery cases
    • D. Sensitivity labels
    Show answer

    D. Sensitivity labels

    Sensitivity labels from Microsoft Purview Information Protection can be configured to automatically apply encryption and other protection settings to documents as they are saved or created in locations like OneDrive for Business, ensuring data is protected at rest and in transit.

  19. 19. A user reports that their corporate-owned Android device, enrolled in Intune as a Fully Managed device, is not receiving company-specific applications deployed through Intune. You verify that the apps are assigned to the correct user group and the device is compliant. Which critical component on the Android device is responsible for receiving and installing these applications and should be checked first?

    Manage identity and compliance (10-15%)

    • A. Google Play Store app
    • B. Microsoft Edge browser
    • C. Company Portal app
    • D. Managed Google Play store
    Show answer

    D. Managed Google Play store

    For Android Enterprise Fully Managed devices, applications are deployed and managed through the Managed Google Play store. This is the dedicated app store for corporate apps on these device types, not the regular Google Play Store or the Company Portal (which is used for enrollment and some app deployments on other Android types).

  20. 20. A company needs to ensure that all Microsoft Teams chat messages, including private chats and channel messages, are retained for a minimum of five years for regulatory compliance. After this period, they should be automatically deleted. Which Microsoft Purview feature should be configured?

    Manage identity and compliance (10-15%)

    • A. Retention policy
    • B. Communication compliance policy
    • C. eDiscovery hold
    • D. Data Loss Prevention (DLP) policy
    Show answer

    A. Retention policy

    Retention policies in Microsoft Purview are designed to retain content for a specified period and then automatically delete it, directly addressing the requirement for retaining Teams messages for five years and then deleting them.

  21. 21. An organization needs to ensure that all user-generated content in Microsoft Teams, including chat messages and files, is retained for a minimum of five years for compliance reasons. After five years, the content should be automatically deleted. Which compliance feature in Microsoft 365 should you configure?

    Manage identity and compliance (10-15%)

    • A. Litigation hold
    • B. Communication compliance
    • C. eDiscovery
    • D. Retention policies
    Show answer

    D. Retention policies

    Retention policies in Microsoft 365 are designed to manage the lifecycle of data, allowing organizations to define how long content is kept and when it should be automatically deleted or retained indefinitely, fulfilling the requirement for a minimum retention period and automatic deletion.

  22. 22. A user reports that they are unable to access a specific internal web application from their personal, non-compliant device. The Conditional Access policy for this application requires devices to be 'compliant' and 'managed'. Which setting in the Conditional Access policy is most likely preventing their access?

    Manage identity and compliance (10-15%)

    • A. Grant control: Require multi-factor authentication
    • B. Device state condition
    • C. Client apps condition
    • D. User risk condition
    Show answer

    B. Device state condition

    The 'Device state' condition in Conditional Access policies is used to specify whether a device must be Azure AD joined/registered and/or marked as compliant by Intune. A 'non-compliant' device would be blocked by this condition.

  23. 23. A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices have a specific application, 'ContosoApp.exe', installed and running. If the application is not present or not running, the device should be marked as non-compliant. Which Intune feature should the administrator use to achieve this?

    Manage identity and compliance (10-15%)

    • A. PowerShell script deployment
    • B. Configuration profile (Device features)
    • C. Custom compliance settings
    • D. Win32 app deployment
    Show answer

    C. Custom compliance settings

    Custom compliance settings allow administrators to define compliance rules based on custom scripts (PowerShell) that check for specific application presence or running state. If the script returns a non-compliant status, the device is marked as such.

  24. 24. A Microsoft 365 Endpoint Administrator is configuring a new sensitivity label in Microsoft Purview. The label needs to automatically apply to documents that contain credit card numbers. Which automatic labeling method should the administrator configure?

    Manage identity and compliance (10-15%)

    • A. Client-side automatic labeling
    • B. Azure Information Protection (AIP) scanner
    • C. Endpoint Data Loss Prevention (DLP)
    • D. Service-side automatic labeling
    Show answer

    D. Service-side automatic labeling

    Service-side automatic labeling applies sensitivity labels to content at rest in SharePoint Online, OneDrive for Business, and Exchange Online based on content matching rules, such as detecting credit card numbers.

  25. 25. A company policy dictates that all corporate-owned Windows 11 devices must have BitLocker encryption enabled and require a PIN at startup. You need to configure Microsoft Intune to enforce this policy. Which type of policy should you use?

    Manage identity and compliance (10-15%)

    • A. Device compliance policy
    • B. App protection policy
    • C. Configuration profile
    • D. Conditional Access policy
    Show answer

    A. Device compliance policy

    Device compliance policies are used to define the security and health requirements that devices must meet to be considered compliant. BitLocker encryption and PIN requirements are common compliance settings.

Microsoft 365 Endpoint Administrator flashcards

Tap a card to flip it. 130 flashcards in the full deck.

  • Sensitivity Label Publishing

    Flip card

    The process of making a created sensitivity label available to specific users or groups within an organization so they can apply it to their content.

    • Labels are useless until published.
    • Published via label policies in Microsoft Purview.
    • Targeted to specific users/groups.
    Study this card →
  • Conditional Access Location Condition

    Flip card

    A feature within Microsoft Entra Conditional Access that allows administrators to define access policies based on the network location from which a user is attempting to access resources.

    • Can restrict access from specific countries/regions.
    • Can require MFA when accessing from untrusted locations.
    • Requires named locations to be configured in Microsoft Entra ID.
    Study this card →
  • Intune Compliance Policy

    Flip card

    A set of rules in Microsoft Intune that devices must meet to be considered compliant. Non-compliant devices can be restricted from accessing corporate resources.

    • Defines device health and configuration requirements.
    • Can include settings for passcodes, OS versions, encryption, and jailbreak detection.
    • Integrates with Conditional Access to enforce access for compliant devices only.
    Study this card →
  • Intune Security Baselines

    Flip card

    Pre-configured groups of settings for Windows devices that align with security best practices recommended by Microsoft, designed for easy deployment.

    • Simplifies deployment of security configurations.
    • Based on Microsoft's security recommendations.
    • Can be customized and assigned to groups.
    Study this card →
  • Azure AD Connect

    Flip card

    A Microsoft tool designed to meet and accomplish your hybrid identity goals. It synchronizes user identities, groups, and device objects between on-premises Active Directory and Azure Active Directory.

    • Handles synchronization of user accounts, groups, and device objects.
    • Supports password hash synchronization, pass-through authentication, and federation.
    • Essential for hybrid identity scenarios, including object lifecycle management (creation, updates, deletions).
    Study this card →
  • Automatic MDM Enrollment (Azure AD Premium)

    Flip card

    A feature in Azure AD that allows devices to automatically enroll in a Mobile Device Management (MDM) solution like Intune when they are joined to Azure AD or registered with Azure AD.

    • Requires Azure AD Premium license.
    • Configured in Azure AD > Mobility (MDM and MAM).
    • Applies to devices that are Azure AD joined or Hybrid Azure AD joined.
    Study this card →
  • Conditional Access

    Flip card

    A feature of Azure Active Directory that enables organizations to enforce policies for accessing resources based on specific conditions, such as user location, device state, application, and sign-in risk.

    • Acts as a gatekeeper for resource access.
    • Can require multi-factor authentication, compliant devices, or trusted locations.
    • Integrates with Intune for device compliance checks.
    Study this card →
  • Intune PowerShell Script Deployment

    Flip card

    A feature in Microsoft Intune that allows administrators to upload and deploy custom PowerShell scripts to Windows devices, providing options for execution context, retry behavior, and reporting.

    • Supports running scripts in user or system context.
    • Provides success/failure reporting for script execution.
    • Ideal for automating tasks, configuring settings not available via profiles, or running diagnostics.
    Study this card →
  • Android Enterprise (Work profile)

    Flip card

    An Intune enrollment method for corporate-owned Android devices that creates a separate work profile to isolate and manage corporate apps and data, while allowing personal use of the device.

    • Separates corporate and personal data.
    • IT manages only the work profile.
    • Suitable for corporate-owned devices with personal use.
    Study this card →
  • Conditional Access Policy Exclusions

    Flip card

    Specific users, groups, or roles that are intentionally excluded from the scope of a Conditional Access policy, often as a safety measure to prevent administrative lockouts.

    • Global Administrator role is often excluded by default from new CA policies.
    • Exclusions take precedence over inclusions.
    • Critical for maintaining access in case of misconfigured policies.
    Study this card →
  • Corporate-Owned, Single-Purpose (COSU) Device Enrollment

    Flip card

    Enrollment methods for corporate-owned mobile devices designed for specific functions (e.g., kiosk, digital signage, frontline worker tools) that offer high levels of management and often zero-touch deployment.

    • Examples: Apple Automated Device Enrollment (ADE), Android Enterprise Dedicated Devices.
    • Provides granular control over device settings, apps, and restrictions.
    • Simplifies initial setup for end-users, often requiring no user interaction.
    Study this card →
  • Apple Business Manager (ABM) Enrollment

    Flip card

    A zero-touch enrollment method for corporate-owned iOS/iPadOS devices purchased directly from Apple, allowing automatic MDM enrollment during initial device setup.

    • Requires integration with Intune.
    • Provides automatic, mandatory enrollment.
    • Ideal for large-scale corporate deployments.
    Study this card →
  • Azure AD Device States and Compliance

    Flip card

    Azure AD device states (Registered, Joined, Hybrid Joined) define how a device connects to Azure AD, while Intune compliance status indicates if it meets organizational policies.

    • Registered: BYOD, provides SSO.
    • Joined/Hybrid Joined: Corporate, full management.
    • Compliance requires MDM (e.g., Intune) evaluation.
    Study this card →
  • Conditional Access: Locations Condition

    Flip card

    A condition in Conditional Access policies that allows defining trusted or untrusted network locations (IP ranges, countries) to control access to resources.

    • Uses named locations (IP ranges).
    • Can include or exclude specific locations.
    • Essential for geographically restricted access.
    Study this card →
  • Conditional Access Device State Condition

    Flip card

    A condition within Conditional Access policies that allows administrators to define access requirements based on the management and compliance status of a device (e.g., Compliant, Hybrid Azure AD joined, Azure AD registered).

    • Crucial for enforcing 'managed device' or 'compliant device' access policies.
    • Leverages Intune's device compliance status.
    • Can be combined with other conditions for granular control.
    Study this card →
  • Conditional Access: Require Compliant Device

    Flip card

    A grant control in Conditional Access that mandates a device must be marked as compliant by an MDM solution (like Intune) to gain access to protected resources.

    • Enforces device health and security standards.
    • Integrates with Intune compliance policies.
    • Fundamental for Zero Trust device access.
    Study this card →
  • Intune Policy Assignment

    Flip card

    The process of linking a created policy (e.g., compliance, configuration, app protection) to specific user groups or device groups within Microsoft Intune, enabling the policy to be evaluated and enforced on those targets.

    • Policies are inactive until assigned.
    • Can be assigned to user groups or device groups.
    • Assignment determines the scope of policy application.
    Study this card →
  • Sensitivity Labels (Microsoft Purview)

    Flip card

    Labels that classify and protect organizational data, allowing for the automatic application of encryption, access restrictions, visual markings, and other protection settings based on data sensitivity.

    • Part of Microsoft Purview Information Protection (MPIP).
    • Can be applied manually by users or automatically by policies.
    • Enforce protection like encryption and access control, persistent with the data.
    Study this card →
  • Managed Google Play

    Flip card

    A customized version of the Google Play Store for Android Enterprise deployments, used by IT administrators to approve, distribute, and manage applications for corporate-managed Android devices.

    • Integrates with Intune for app management on Android Enterprise devices.
    • IT admins approve apps before they are available to users/devices.
    • Used for both public apps and private line-of-business (LOB) apps.
    Study this card →
  • Retention Policy (Microsoft Purview)

    Flip card

    A policy that defines how long an organization keeps content (e.g., emails, documents, Teams messages) and, optionally, when to delete it after the retention period.

    • Retains content for compliance.
    • Can also automatically delete content.
    • Applies across various Microsoft 365 services.
    Study this card →
  • Retention Policies (Microsoft Purview)

    Flip card

    Rules that govern the lifecycle of data within Microsoft 365, specifying how long content should be retained (or deleted) to meet regulatory, legal, and business requirements.

    • Apply to various locations: Exchange mailboxes, SharePoint sites, OneDrive accounts, Teams chats/channels.
    • Can retain content for a specified period, delete content after a period, or both.
    • Prevent permanent deletion during the retention period.
    Study this card →
  • Conditional Access: Device State

    Flip card

    A condition in Conditional Access policies that evaluates whether a device is Azure AD registered/joined and/or compliant with Intune policies, influencing access decisions.

    • Checks device registration/join status.
    • Verifies device compliance from Intune.
    • Critical for 'trusted device' access scenarios.
    Study this card →
  • Intune Custom Compliance Settings

    Flip card

    Allows administrators to extend Intune's compliance capabilities by defining custom rules using PowerShell scripts, enabling checks for specific device configurations or application states.

    • Uses PowerShell scripts to evaluate compliance.
    • Enables checks beyond built-in compliance settings.
    • Reports device compliance status back to Intune.
    Study this card →
  • Service-Side Automatic Labeling

    Flip card

    A Microsoft Purview feature that automatically applies sensitivity labels to content at rest in cloud services (e.g., SharePoint, OneDrive, Exchange) based on defined conditions.

    • Applies labels to existing content in cloud locations.
    • Uses sensitive information types (SITs) for detection.
    • Does not require user interaction for application.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.