1. A company policy states that all highly confidential emails sent from Exchange Online must be encrypted and prevent forwarding. The administrator has already created a sensitivity label named 'Highly Confidential' with the appropriate encryption and content marking settings. Which additional step is required to enforce the 'prevent forwarding' restriction when users apply this label?
Manage identity and compliance (10-15%)
A.Ensure the sensitivity label is published to end-users.
B.Configure an Exchange mail flow rule (transport rule).
C.Enable Azure Information Protection (AIP) Unified Labeling client.
D.Configure a Data Loss Prevention (DLP) policy in Microsoft Purview.
Show answerAnswer
A. Ensure the sensitivity label is published to end-users.
For users to be able to apply a sensitivity label and for its associated protection settings (like encryption and 'prevent forwarding') to take effect, the label must first be published to them via a label policy.
2. A Microsoft 365 Endpoint Administrator needs to configure Microsoft Intune to apply specific security settings to devices based on their geographical location. For example, devices accessing corporate data from outside the corporate network should have a stricter set of security policies applied. Which feature in Microsoft Intune should the administrator use to achieve this dynamic policy application?
Manage identity and compliance (10-15%)
A.Device compliance policies
B.Conditional Access policies
C.Configuration profiles
D.Security baselines
Show answerAnswer
B. Conditional Access policies
Conditional Access policies are designed to enforce conditions for accessing resources, including location-based restrictions. They work by evaluating signals like user, device, location, and application, then enforcing access decisions.
3. An organization uses Microsoft Intune to manage its corporate-owned iOS devices. A new security policy requires that all iOS devices must have a passcode set, and this passcode must meet a minimum complexity requirement. Additionally, if a device is found to be non-compliant with this passcode policy, it should automatically be marked as non-compliant in Intune. Which Intune configuration should the administrator use to implement this policy?
Manage identity and compliance (10-15%)
A.Deploy a custom PowerShell script via Intune.
B.Create a device restriction profile for iOS.
C.Configure a compliance policy for iOS.
D.Set up an App Protection Policy (APP) for iOS.
Show answerAnswer
C. Configure a compliance policy for iOS.
Compliance policies in Intune are specifically designed to define the conditions that devices must meet to be considered compliant, such as passcode requirements. They also include actions for non-compliance.
4. An organization uses Microsoft Intune to manage its Windows 11 devices. A new security baseline has been released by Microsoft, and the security team wants to apply it to all corporate devices. Which Intune feature should the administrator use to quickly deploy and manage these recommended security settings?
Manage identity and compliance (10-15%)
A.Device compliance policies
B.Security baselines
C.Custom OMA-URI settings
D.Configuration policies
Show answerAnswer
B. Security baselines
Security baselines in Intune are pre-configured groups of Windows settings that help secure devices according to best practices recommended by Microsoft and security teams, making them ideal for deploying new security standards.
5. A company has a hybrid Azure AD environment. All user accounts are synchronized from on-premises Active Directory. You need to ensure that when a user's account is deleted from the on-premises Active Directory, their corresponding Azure AD account is also automatically deleted, and their enrolled devices are deprovisioned from Intune. Which component is responsible for synchronizing these deletions from on-premises to Azure AD?
Manage identity and compliance (10-15%)
A.Azure AD Connect
B.Microsoft Defender for Identity
C.Azure AD Connect Health
D.Azure AD Domain Services
Show answerAnswer
A. Azure AD Connect
Azure AD Connect is the tool responsible for synchronizing identities between on-premises Active Directory and Azure Active Directory. This includes user accounts, groups, and the synchronization of changes like deletions.
6. A company policy requires that all corporate-owned Windows 11 devices automatically enroll into Microsoft Intune when a user signs in for the first time with their Azure AD account. You need to configure this automatic enrollment. Which method should you implement?
Manage identity and compliance (10-15%)
A.Group Policy Object (GPO) for Hybrid Azure AD Join
B.Manual MDM enrollment via Company Portal
C.Automatic MDM enrollment via Azure AD Premium
D.Bulk enrollment using Windows Autopilot
Show answerAnswer
C. Automatic MDM enrollment via Azure AD Premium
Automatic MDM enrollment for Windows devices linked to Azure AD Premium allows devices to automatically enroll in Intune when users sign in with their Azure AD accounts, fulfilling the requirement for corporate-owned devices upon first sign-in.
7. A user reports that they cannot access a specific SharePoint Online site from their personal laptop, which is not enrolled in Intune. The error message indicates that their device does not meet the organization's compliance requirements. You have already verified that the user's account is enabled and has the correct permissions to the SharePoint site. Which policy type is most likely preventing access?
Manage identity and compliance (10-15%)
A.App protection policy
B.Device compliance policy
C.Device configuration profile
D.Conditional Access policy
Show answerAnswer
D. Conditional Access policy
Conditional Access policies are used to enforce access restrictions based on various conditions, including device state (e.g., 'compliant' or 'hybrid Azure AD joined'). An unmanaged personal laptop would likely fail a Conditional Access policy requiring a compliant device.
8. A Microsoft 365 Endpoint Administrator needs to deploy a custom PowerShell script to all Windows 10/11 devices managed by Intune. The script needs to run with system context and report its execution status. Which Intune feature should the administrator use to deploy this script?
Manage identity and compliance (10-15%)
A.Microsoft Store app deployment
B.PowerShell scripts in Intune
C.Win32 app deployment
D.Device configuration profile (Custom OMA-URI)
Show answerAnswer
B. PowerShell scripts in Intune
Intune's dedicated PowerShell scripts feature allows administrators to upload custom PowerShell scripts, assign them to groups, and configure them to run in system or user context, with detailed reporting on execution status. This directly matches the requirements.
9. A company policy requires that all corporate-owned Android devices must have a work profile for separating corporate and personal data. Additionally, all apps installed within the work profile must be approved by IT. Which Intune enrollment profile should be used for these devices?
Manage identity and compliance (10-15%)
A.Android Enterprise (Fully managed)
B.Android device administrator
C.Android Enterprise (Dedicated devices)
D.Android Enterprise (Work profile)
Show answerAnswer
D. Android Enterprise (Work profile)
Android Enterprise (Work profile) enrollment is specifically designed for corporate-owned devices where personal use is allowed but corporate data and apps need to be isolated and managed within a separate work profile.
10. An administrator is configuring a new Conditional Access policy to require multi-factor authentication (MFA) for all users accessing SharePoint Online from outside the corporate network. After creating the policy, the administrator tests it with their own account, which is a global administrator. The policy does not trigger MFA. What is the most likely reason for this behavior?
Manage identity and compliance (10-15%)
A.MFA is not enabled for the administrator's account.
B.Global Administrators are exempt from Conditional Access policies by default.
C.The administrator's device is already marked as compliant.
D.The policy was not assigned to the correct user group.
Show answerAnswer
B. Global Administrators are exempt from Conditional Access policies by default.
By default, Global Administrator accounts are excluded from Conditional Access policies to prevent accidental lockout. This is a crucial safety measure in Azure AD. To test such policies, a non-admin test account or a specific exclusion override is required.
11. A global manufacturing company needs to manage mobile devices (iOS and Android) for its frontline workers. These devices are corporate-owned and will be used exclusively for work-related tasks, with minimal user interaction required for setup. The company wants to ensure strict control over app installations and device settings. Which Intune enrollment method would be most suitable for these devices?
Manage identity and compliance (10-15%)
A.Automated Device Enrollment (ADE) for iOS or Android Enterprise dedicated devices
B.Device enrollment manager (DEM)
C.User enrollment
D.Bring Your Own Device (BYOD)
Show answerAnswer
A. Automated Device Enrollment (ADE) for iOS or Android Enterprise dedicated devices
For corporate-owned devices used for specific work tasks with strict control and minimal user interaction, Automated Device Enrollment (ADE) for iOS/iPadOS or Android Enterprise dedicated devices (formerly Kiosk/COSU) are the most suitable methods. These provide powerful management capabilities and simplify initial setup.
12. An administrator needs to configure Intune to automatically enroll all new corporate-owned iOS/iPadOS devices without requiring user interaction during the initial setup. The devices are purchased directly from Apple. Which enrollment method should be used?
Manage identity and compliance (10-15%)
A.Apple Configurator
B.Direct enrollment
C.Apple Business Manager (ABM) / Apple School Manager (ASM)
D.Device enrollment manager (DEM)
Show answerAnswer
C. Apple Business Manager (ABM) / Apple School Manager (ASM)
Apple Business Manager (ABM) or Apple School Manager (ASM) integration with Intune allows for automated, zero-touch enrollment of corporate-owned iOS/iPadOS devices purchased directly from Apple, ensuring they are enrolled during initial setup.
13. A global company needs to ensure that all user devices accessing corporate resources are registered with Azure Active Directory (Azure AD) and are compliant with company policies. This includes personal mobile devices (BYOD) and corporate laptops. Which Azure AD device state fully satisfies both requirements?
Manage identity and compliance (10-15%)
A.Hybrid Azure AD joined
B.Azure AD registered and Intune compliant
C.Azure AD registered
D.Azure AD joined
Show answerAnswer
B. Azure AD registered and Intune compliant
To ensure devices are registered and compliant, they must first be registered (Azure AD Registered for BYOD, or Joined/Hybrid Joined for corporate) and then explicitly marked as 'compliant' by a management solution like Intune. 'Azure AD registered and Intune compliant' covers both conditions for all device types.
14. A Microsoft 365 Endpoint Administrator wants to ensure that users can only access corporate resources from specific IP ranges within the company's network. If a user attempts to access resources from outside these IP ranges, access should be blocked. Which Conditional Access condition should be configured?
Manage identity and compliance (10-15%)
A.Sign-in risk
B.Locations
C.User risk
D.Device platforms
Show answerAnswer
B. Locations
The 'Locations' condition in Conditional Access policies allows administrators to define trusted IP ranges (named locations) and then either include or exclude them from policy application, directly addressing the need to restrict access based on network location.
15. A company is implementing a new policy to restrict access to Microsoft 365 services. Users should only be able to access Exchange Online and SharePoint Online from devices that are either compliant or Hybrid Azure AD joined. Access from any other device state should be blocked. Which type of Conditional Access policy condition should you configure to enforce this requirement?
Manage identity and compliance (10-15%)
A.Conditions > Device state
B.Conditions > Device platforms
C.Users and groups
D.Cloud apps or actions
Show answerAnswer
A. Conditions > Device state
The 'Device state' condition in Conditional Access policies allows you to specify whether a device must be 'Compliant' or 'Hybrid Azure AD joined' to gain access, directly addressing the requirement to restrict access based on the device's managed status.
16. A company is implementing a Zero Trust security model. They want to ensure that access to highly sensitive applications is only granted from devices that are considered 'trusted'. For Windows 11 devices, this means they must be Azure AD joined and compliant with Intune policies. Which type of Conditional Access grant control should be configured?
Manage identity and compliance (10-15%)
A.Require multi-factor authentication
B.Require Hybrid Azure AD join
C.Require device to be marked as compliant
D.Require approved client app
Show answerAnswer
C. Require device to be marked as compliant
The 'Require device to be marked as compliant' grant control in Conditional Access ensures that only devices that meet the organization's compliance policies (as defined in Intune) are granted access, aligning with the 'trusted device' requirement of Zero Trust.
17. A company uses Microsoft Intune to manage its devices. A new compliance policy states that all Windows 11 devices must have BitLocker enabled and a specific Windows Defender Antivirus configuration. You create a new device compliance policy in Intune for Windows 11. To ensure this policy is enforced, what is the next crucial step after creating the policy?
Manage identity and compliance (10-15%)
A.Assign the compliance policy to a group of users or devices.
B.Configure a Conditional Access policy to block non-compliant devices.
C.Create an App protection policy for Windows devices.
D.Manually restart all Windows 11 devices to apply the policy.
Show answerAnswer
A. Assign the compliance policy to a group of users or devices.
After creating any policy in Intune, it must be assigned to a group of users or devices for it to take effect. Without assignment, the policy exists but is not applied to any endpoints.
18. A company policy requires that all documents saved to OneDrive for Business from corporate-managed Windows devices must be encrypted. You need to implement a solution that automatically enforces this encryption for new and existing files. Which Microsoft 365 compliance feature should you configure?
Manage identity and compliance (10-15%)
A.Data Loss Prevention (DLP) policies
B.Retention policies
C.eDiscovery cases
D.Sensitivity labels
Show answerAnswer
D. Sensitivity labels
Sensitivity labels from Microsoft Purview Information Protection can be configured to automatically apply encryption and other protection settings to documents as they are saved or created in locations like OneDrive for Business, ensuring data is protected at rest and in transit.
19. A user reports that their corporate-owned Android device, enrolled in Intune as a Fully Managed device, is not receiving company-specific applications deployed through Intune. You verify that the apps are assigned to the correct user group and the device is compliant. Which critical component on the Android device is responsible for receiving and installing these applications and should be checked first?
Manage identity and compliance (10-15%)
A.Google Play Store app
B.Microsoft Edge browser
C.Company Portal app
D.Managed Google Play store
Show answerAnswer
D. Managed Google Play store
For Android Enterprise Fully Managed devices, applications are deployed and managed through the Managed Google Play store. This is the dedicated app store for corporate apps on these device types, not the regular Google Play Store or the Company Portal (which is used for enrollment and some app deployments on other Android types).
20. A company needs to ensure that all Microsoft Teams chat messages, including private chats and channel messages, are retained for a minimum of five years for regulatory compliance. After this period, they should be automatically deleted. Which Microsoft Purview feature should be configured?
Manage identity and compliance (10-15%)
A.Retention policy
B.Communication compliance policy
C.eDiscovery hold
D.Data Loss Prevention (DLP) policy
Show answerAnswer
A. Retention policy
Retention policies in Microsoft Purview are designed to retain content for a specified period and then automatically delete it, directly addressing the requirement for retaining Teams messages for five years and then deleting them.
21. An organization needs to ensure that all user-generated content in Microsoft Teams, including chat messages and files, is retained for a minimum of five years for compliance reasons. After five years, the content should be automatically deleted. Which compliance feature in Microsoft 365 should you configure?
Manage identity and compliance (10-15%)
A.Litigation hold
B.Communication compliance
C.eDiscovery
D.Retention policies
Show answerAnswer
D. Retention policies
Retention policies in Microsoft 365 are designed to manage the lifecycle of data, allowing organizations to define how long content is kept and when it should be automatically deleted or retained indefinitely, fulfilling the requirement for a minimum retention period and automatic deletion.
22. A user reports that they are unable to access a specific internal web application from their personal, non-compliant device. The Conditional Access policy for this application requires devices to be 'compliant' and 'managed'. Which setting in the Conditional Access policy is most likely preventing their access?
The 'Device state' condition in Conditional Access policies is used to specify whether a device must be Azure AD joined/registered and/or marked as compliant by Intune. A 'non-compliant' device would be blocked by this condition.
23. A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices have a specific application, 'ContosoApp.exe', installed and running. If the application is not present or not running, the device should be marked as non-compliant. Which Intune feature should the administrator use to achieve this?
Manage identity and compliance (10-15%)
A.PowerShell script deployment
B.Configuration profile (Device features)
C.Custom compliance settings
D.Win32 app deployment
Show answerAnswer
C. Custom compliance settings
Custom compliance settings allow administrators to define compliance rules based on custom scripts (PowerShell) that check for specific application presence or running state. If the script returns a non-compliant status, the device is marked as such.
24. A Microsoft 365 Endpoint Administrator is configuring a new sensitivity label in Microsoft Purview. The label needs to automatically apply to documents that contain credit card numbers. Which automatic labeling method should the administrator configure?
Manage identity and compliance (10-15%)
A.Client-side automatic labeling
B.Azure Information Protection (AIP) scanner
C.Endpoint Data Loss Prevention (DLP)
D.Service-side automatic labeling
Show answerAnswer
D. Service-side automatic labeling
Service-side automatic labeling applies sensitivity labels to content at rest in SharePoint Online, OneDrive for Business, and Exchange Online based on content matching rules, such as detecting credit card numbers.
25. A company policy dictates that all corporate-owned Windows 11 devices must have BitLocker encryption enabled and require a PIN at startup. You need to configure Microsoft Intune to enforce this policy. Which type of policy should you use?
Manage identity and compliance (10-15%)
A.Device compliance policy
B.App protection policy
C.Configuration profile
D.Conditional Access policy
Show answerAnswer
A. Device compliance policy
Device compliance policies are used to define the security and health requirements that devices must meet to be considered compliant. BitLocker encryption and PIN requirements are common compliance settings.
A feature within Microsoft Entra Conditional Access that allows administrators to define access policies based on the network location from which a user is attempting to access resources.
Can restrict access from specific countries/regions.
Can require MFA when accessing from untrusted locations.
Requires named locations to be configured in Microsoft Entra ID.
A set of rules in Microsoft Intune that devices must meet to be considered compliant. Non-compliant devices can be restricted from accessing corporate resources.
Defines device health and configuration requirements.
Can include settings for passcodes, OS versions, encryption, and jailbreak detection.
Integrates with Conditional Access to enforce access for compliant devices only.
A Microsoft tool designed to meet and accomplish your hybrid identity goals. It synchronizes user identities, groups, and device objects between on-premises Active Directory and Azure Active Directory.
Handles synchronization of user accounts, groups, and device objects.
Supports password hash synchronization, pass-through authentication, and federation.
Essential for hybrid identity scenarios, including object lifecycle management (creation, updates, deletions).
A feature in Azure AD that allows devices to automatically enroll in a Mobile Device Management (MDM) solution like Intune when they are joined to Azure AD or registered with Azure AD.
Requires Azure AD Premium license.
Configured in Azure AD > Mobility (MDM and MAM).
Applies to devices that are Azure AD joined or Hybrid Azure AD joined.
A feature of Azure Active Directory that enables organizations to enforce policies for accessing resources based on specific conditions, such as user location, device state, application, and sign-in risk.
Acts as a gatekeeper for resource access.
Can require multi-factor authentication, compliant devices, or trusted locations.
Integrates with Intune for device compliance checks.
A feature in Microsoft Intune that allows administrators to upload and deploy custom PowerShell scripts to Windows devices, providing options for execution context, retry behavior, and reporting.
Supports running scripts in user or system context.
Provides success/failure reporting for script execution.
Ideal for automating tasks, configuring settings not available via profiles, or running diagnostics.
An Intune enrollment method for corporate-owned Android devices that creates a separate work profile to isolate and manage corporate apps and data, while allowing personal use of the device.
Separates corporate and personal data.
IT manages only the work profile.
Suitable for corporate-owned devices with personal use.
Specific users, groups, or roles that are intentionally excluded from the scope of a Conditional Access policy, often as a safety measure to prevent administrative lockouts.
Global Administrator role is often excluded by default from new CA policies.
Exclusions take precedence over inclusions.
Critical for maintaining access in case of misconfigured policies.
Enrollment methods for corporate-owned mobile devices designed for specific functions (e.g., kiosk, digital signage, frontline worker tools) that offer high levels of management and often zero-touch deployment.
Examples: Apple Automated Device Enrollment (ADE), Android Enterprise Dedicated Devices.
Provides granular control over device settings, apps, and restrictions.
Simplifies initial setup for end-users, often requiring no user interaction.
A zero-touch enrollment method for corporate-owned iOS/iPadOS devices purchased directly from Apple, allowing automatic MDM enrollment during initial device setup.
Azure AD device states (Registered, Joined, Hybrid Joined) define how a device connects to Azure AD, while Intune compliance status indicates if it meets organizational policies.
A condition in Conditional Access policies that allows defining trusted or untrusted network locations (IP ranges, countries) to control access to resources.
A condition within Conditional Access policies that allows administrators to define access requirements based on the management and compliance status of a device (e.g., Compliant, Hybrid Azure AD joined, Azure AD registered).
Crucial for enforcing 'managed device' or 'compliant device' access policies.
Leverages Intune's device compliance status.
Can be combined with other conditions for granular control.
A grant control in Conditional Access that mandates a device must be marked as compliant by an MDM solution (like Intune) to gain access to protected resources.
The process of linking a created policy (e.g., compliance, configuration, app protection) to specific user groups or device groups within Microsoft Intune, enabling the policy to be evaluated and enforced on those targets.
Policies are inactive until assigned.
Can be assigned to user groups or device groups.
Assignment determines the scope of policy application.
Labels that classify and protect organizational data, allowing for the automatic application of encryption, access restrictions, visual markings, and other protection settings based on data sensitivity.
Part of Microsoft Purview Information Protection (MPIP).
Can be applied manually by users or automatically by policies.
Enforce protection like encryption and access control, persistent with the data.
A customized version of the Google Play Store for Android Enterprise deployments, used by IT administrators to approve, distribute, and manage applications for corporate-managed Android devices.
Integrates with Intune for app management on Android Enterprise devices.
IT admins approve apps before they are available to users/devices.
Used for both public apps and private line-of-business (LOB) apps.
A policy that defines how long an organization keeps content (e.g., emails, documents, Teams messages) and, optionally, when to delete it after the retention period.
Rules that govern the lifecycle of data within Microsoft 365, specifying how long content should be retained (or deleted) to meet regulatory, legal, and business requirements.
Apply to various locations: Exchange mailboxes, SharePoint sites, OneDrive accounts, Teams chats/channels.
Can retain content for a specified period, delete content after a period, or both.
Prevent permanent deletion during the retention period.
A condition in Conditional Access policies that evaluates whether a device is Azure AD registered/joined and/or compliant with Intune policies, influencing access decisions.
Allows administrators to extend Intune's compliance capabilities by defining custom rules using PowerShell scripts, enabling checks for specific device configurations or application states.
A Microsoft Purview feature that automatically applies sensitivity labels to content at rest in cloud services (e.g., SharePoint, OneDrive, Exchange) based on defined conditions.
Applies labels to existing content in cloud locations.
Uses sensitive information types (SITs) for detection.
Does not require user interaction for application.
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.