Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium

A Microsoft 365 Endpoint Administrator needs to deploy a custom PowerShell script to all corporate-owned Windows 11 devices to optimize system performance by clearing temporary files. The script should run with administrator privileges and report its execution status back to Intune. Which Intune feature should be used for this deployment?

  1. ADevices > Scripts > PowerShell scripts
  2. BEndpoint security > Attack surface reduction rules
  3. CConfiguration policies > Custom OMA-URI
  4. DApps > Windows apps > Line-of-business app
Show answer & explanation

Correct answer: A. Devices > Scripts > PowerShell scripts

Intune's 'Scripts' feature under 'Devices' is specifically designed for deploying and managing PowerShell scripts (and shell scripts for macOS/Linux) to devices, allowing configuration of execution context and reporting of script status.

Why the other options are wrong

  • B. Attack surface reduction rules are part of Defender for Endpoint and focus on preventing malicious activity, not running custom system optimization scripts.
  • C. Custom OMA-URI is for deploying specific settings not available in Intune's UI, not for executing arbitrary PowerShell scripts with status reporting.
  • D. Line-of-business apps are for deploying installable applications, not for running standalone PowerShell scripts for system configuration.

Intune PowerShell Script Deployment

A feature in Microsoft Intune that allows administrators to deploy and run custom PowerShell scripts on Windows devices to perform various configuration, automation, or maintenance tasks.

  • Found under 'Devices > Scripts' in Intune.
  • Supports running scripts as System or logged-on user.
  • Provides execution status and error reporting.
  • Ideal for custom configurations or automation not covered by built-in policies.

Memory trick: Scripts are the direct path to device automation.

More Manage devices and apps (55-60%) questions