Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium

A Microsoft 365 Endpoint Administrator needs to deploy a custom script to all corporate-owned Windows 11 devices to optimize system performance. The script runs a series of PowerShell commands. The administrator wants to ensure the script runs only once per device and reports its execution status back to Intune. Which Intune feature should be used?

  1. ADevice configuration profile (Custom OMA-URI)
  2. BPowerShell script via Azure Automation
  3. CWin32 app deployment with a PowerShell wrapper
  4. DScripts policy
Show answer & explanation

Correct answer: D. Scripts policy

Intune's 'Scripts' policy is specifically designed for deploying PowerShell scripts to Windows devices. It provides built-in reporting of script execution status and offers options to run scripts once or repeatedly, making it ideal for this scenario.

Why the other options are wrong

  • A. Custom OMA-URI is for configuring specific CSP settings, not executing arbitrary PowerShell scripts directly.
  • B. Azure Automation can execute scripts, but integrating it for direct deployment to Intune-managed devices for this purpose is more complex than using Intune's native script feature.
  • C. While possible, using a Win32 app for a simple PowerShell script is overly complex and less direct than a dedicated scripts policy.

Intune Scripts Policy (PowerShell)

An Intune feature for deploying and managing PowerShell scripts on Windows devices, offering execution status reporting and run-once options.

  • Dedicated policy type for PowerShell scripts
  • Provides execution status reporting in Intune
  • Can be configured to run once or repeatedly
  • Supports running with user or system context

Memory trick: Scripts Simplify System Setup, Reporting Status Up.

More Manage devices and apps (55-60%) questions