Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Easy

A Microsoft 365 Endpoint Administrator needs to deploy a custom security script to a specific group of Windows 11 devices managed by Intune. The script must run with system permissions and only once. Which Intune feature should the administrator use?

  1. AWin32 app deployment
  2. BDevice configuration profile (custom OMA-URI)
  3. CPowerShell scripts in Intune
  4. DMicrosoft Store app deployment
Show answer & explanation

Correct answer: C. PowerShell scripts in Intune

Microsoft Intune offers a dedicated feature for deploying PowerShell scripts to Windows devices. This feature allows administrators to configure scripts to run with system context and specify execution frequency, including running only once.

Why the other options are wrong

  • A. Win32 app deployment is for installing applications, not for running standalone scripts.
  • B. While custom OMA-URI can deploy some settings, it's not the primary or most flexible method for running a complex PowerShell script.
  • D. Microsoft Store app deployment is for distributing apps from the Microsoft Store, not custom scripts.

Intune PowerShell Script Deployment

Microsoft Intune allows administrators to deploy custom PowerShell scripts to Windows devices, enabling advanced configuration, automation, and remediation tasks.

  • Supports running scripts with user or system context.
  • Can be configured to run once, or repeatedly.
  • Provides detailed reporting on script execution status.
  • Ideal for custom security or configuration tasks.

Memory trick: When you need to 'script' a custom action, Intune's PowerShell feature is your best actor.

More Manage identity and compliance (10-15%) questions