Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium

A Microsoft 365 Endpoint Administrator needs to create a Wi-Fi profile for corporate-owned iOS devices. The profile must ensure secure authentication using client certificates and encrypt all traffic. The network infrastructure uses WPA2-Enterprise with EAP-TLS. Which security type should be selected when configuring the Wi-Fi profile in Microsoft Intune?

  1. AWPA/WPA2-Enterprise (EAP)
  2. BWEP
  3. CWPA2-Personal
  4. DOpen (no encryption)
Show answer & explanation

Correct answer: A. WPA/WPA2-Enterprise (EAP)

WPA/WPA2-Enterprise (EAP) is the correct security type for networks requiring secure authentication methods like EAP-TLS, which uses client certificates for identity verification and provides robust encryption for corporate environments.

Why the other options are wrong

  • B. WEP is an outdated and insecure encryption protocol that should not be used in any modern network.
  • C. WPA2-Personal uses a pre-shared key (PSK) and is designed for home or small office use, not for enterprise-grade security with certificates.
  • D. An open network provides no encryption or authentication, making it highly insecure and unsuitable for corporate data.

Intune Wi-Fi EAP-TLS Profile

A Wi-Fi configuration profile in Microsoft Intune that configures devices to connect to WPA2-Enterprise networks using EAP-TLS for certificate-based authentication.

  • Uses EAP-TLS for strong authentication.
  • Requires client certificates.
  • Encrypts traffic on WPA2-Enterprise networks.
  • Designed for corporate security.

Memory trick: Enterprise EAP is the key to secure corporate Wi-Fi with certificates.

More Manage devices and apps (55-60%) questions