Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium

A Microsoft 365 Endpoint Administrator needs to configure a custom setting on Windows 11 devices that is not available through standard Intune device configuration profiles. The setting requires modifying a specific registry key value. Which Intune profile type should be used?

  1. ADevice restrictions (Windows 10 and later)
  2. BAdministrative Templates
  3. CIdentity protection
  4. DCustom (OMA-URI)
Show answer & explanation

Correct answer: D. Custom (OMA-URI)

When a specific setting is not exposed in standard Intune profiles, a 'Custom (OMA-URI)' profile can be used to directly configure settings via Open Mobile Alliance Uniform Resource Identifier, which can include registry modifications.

Why the other options are wrong

  • A. Device restrictions cover common settings but not every possible registry key.
  • B. Administrative Templates cover settings found in Group Policy but not arbitrary registry keys not exposed via ADMX.
  • C. Identity protection focuses on user identities and sign-in risks, not device configuration settings.

Intune Custom OMA-URI Profile

A Microsoft Intune profile type that allows administrators to configure custom settings on devices using Open Mobile Alliance Uniform Resource Identifier (OMA-URI) strings, typically mapping to Configuration Service Providers (CSPs).

  • Used for settings not available in standard Intune profiles.
  • Requires knowledge of OMA-URI paths and corresponding CSPs.
  • Can be used to modify registry values indirectly via CSPs.

Memory trick: OMA-URI for the settings you can't see.

More Manage devices and apps (55-60%) questions