Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Hard

A Microsoft 365 Endpoint Administrator needs to configure a Wi-Fi profile for corporate-owned iOS devices. The profile must require users to authenticate with their Azure Active Directory credentials and ensure that communication is secured using TLS. Which authentication method should be selected in the Wi-Fi profile?

  1. AWPA2-Personal
  2. BEAP-PEAP
  3. CEAP-TLS
  4. DPre-shared key (PSK)
Show answer & explanation

Correct answer: B. EAP-PEAP

To authenticate with Azure AD credentials and secure communication with TLS, EAP-PEAP (Protected Extensible Authentication Protocol) with MSCHAPv2 is commonly used. EAP-TLS uses client certificates, not Azure AD credentials directly for the client side.

Why the other options are wrong

  • A. WPA2-Personal uses a Pre-Shared Key, similar to option A, and does not support Azure AD authentication.
  • C. EAP-TLS uses client certificates for authentication, not Azure AD usernames and passwords directly for the client side, although it provides strong TLS security.
  • D. PSK uses a shared password for all users and does not integrate with Azure AD credentials or provide per-user authentication.

Intune Wi-Fi EAP-PEAP Profile

A Wi-Fi profile configuration in Intune for iOS devices that uses EAP-PEAP for secure authentication, typically with username/password credentials (e.g., Azure AD).

  • Uses a server certificate to establish a TLS tunnel.
  • Authenticates user credentials (e.g., username/password) within the protected tunnel.
  • Commonly used with RADIUS servers for enterprise authentication.

Memory trick: PEAP for passwords, TLS for certificates.

More Manage devices and apps (55-60%) questions