You have a Microsoft 365 subscription that uses Microsoft Intune Suite.
You use Microsoft Intune to manage devices.
Auto-enrollment in Intune is configured.
You have 100 Windows 11 devices in a workgroup.
You need to connect the devices to the corporate wireless network and enroll 100 new Windows 11 devices in Intune.
What should you use?
A. a provisioning package B. a Group Policy Object (GPO) C. mobile device management (MDM) automatic enrollment D. a device configuration policy
A. a provisioning package
Question 203:
HOTSPOT
You have devices enrolled in Microsoft Intune as shown in the following table.
You need to identify the following:
1. Device you can remove from Intune by using the Wipe action.
2. The enrollment state and the associated user account can be retained on devices that are wiped.
What should you identify? To answer, select the appropriate options in the answer area.
Question 204:
You have a Microsoft 365 E5 subscription that contains 10 Android Enterprise devices. Each device has a corporate-owned work profile and is enrolled in Microsoft Intune.
You need to configure the devices to run a single app in kiosk mode.
Which Configuration settings should you modify in the device restrictions profile?
A. Users and Accounts B. General C. System security D. Device experience
D. Device experience
Explanation
Android Enterprise device settings list to allow or restrict features on corporate-owned devices using Intune
Device experience
Use these settings to configure a kiosk-style experience on your dedicated devices, or to customize the home screen experiences on your fully managed devices. You can configure devices to run one app, or run many apps. When a device is set with kiosk mode, only the apps you add are available.
Note: You can control and restrict on Android Enterprise devices owned by your organization. As part of your mobile device management (MDM) solution, use these settings to allow or disable features, run apps on dedicated devices, control security, and more.
You have 100 computers that run Windows 10. The computers are joined to Azure AD and enrolled in Microsoft Intune.
You need to configure the following device restrictions:
1. Block users from browsing to suspicious websites.
2. Scan all scripts loaded into Microsoft Edge.
Which two settings should you configure in the Device restrictions configuration profile? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.
Question 206:
You have computers that run Windows 10 and connect to an Azure Log Analytics workspace. The workspace is configured to collect all available events from the Windows event logs.
The computers have the logged events shown in the following table.
Which events are collected in the Log Analytics workspace?
A. 1 only B. 2 and 3 only C. 1 and 3 only D. 1, 2, and 4 only E. 1, 2, 3, and 4
D. 1, 2, and 4 only
Explanation
Collect Windows event log data sources with Log Analytics agent
Windows event logs are one of the most common data sources for Log Analytics agents on Windows virtual machines because many applications write to the Windows event log. You can collect events from standard logs, such as System and Application, and any custom logs created by applications you need to monitor.
You have a Microsoft 365 tenant that uses Microsoft Intune.
From the Microsoft Intune admin center, you plan to create a baseline to monitor the Startup score and the App reliability score of enrolled Windows 10 devices.
You need to identify which tool to use to create the baseline and the minimum number of devices required to create the baseline.
What should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Box 1: Endpoint analytics
Endpoint analytics has the following three items are central to understanding each of the reports:
Scores
Baselines
Insights and recommendations Box 2: 5
A status of insufficient data means you don't have enough devices reporting to provide a meaningful score. Currently, at least five devices are required.
You need to enroll Android Enterprise devices in Microsoft Intune by using zero-touch enrollment.
What should you do first?
A. From the Microsoft Intune admin center, configure enrollment restrictions. B. From the Microsoft Intune admin center, create a zero-touch configuration. C. From the Microsoft Intune admin center, link a Managed Google Play account. D. From the zero-touch enrollment portal, create a zero-touch configuration.
C. From the Microsoft Intune admin center, link a Managed Google Play account.
Explanation
Before you can enroll Android Enterprise devices using zero-touch enrollment in Microsoft Intune, the first step is to link a Managed Google Play account to Microsoft Intune. This is necessary because Android Enterprise management, including zero-touch enrollment, relies on the Managed Google Play account to manage and deploy apps and policies to Android devices. After linking the account, you can proceed with setting up the zero-touch configuration.
Question 209:
You need to prepare for the deployment of the Phoenix office computers.
What should you do first?
A. Generalize the computers and configure the Device settings from the Microsoft Entra admin center. B. Extract the serial number of each computer to an XML file and upload the file from the Microsoft Intune admin center. C. Extract the hardware ID information of each computer to a CSV file and upload the file from the Microsoft Intune admin center. D. Generalize the computers and configure the Mobility (MDM and MAM) settings from the Microsoft Entra admin center. E. Extract the serial number information of each computer to a CSV file and upload the file from the Microsoft Intune admin center.
C. Extract the hardware ID information of each computer to a CSV file and upload the file from the Microsoft Intune admin center.
Explanation
To manage devices through Microsoft Store for Business and Education, you'll need a .csv file that contains specific information about the devices. You should be able to get this from your Microsoft account contact, or the store where you purchased the devices. Upload the .csv file to Microsoft Store to add the devices.
Note:
Provide new computers to the Phoenix office users. The new computers have Windows 10 Pro preinstalled and were purchased already.
Deploy Windows 10 Enterprise to the computers of the Phoenix office users by using Windows Autopilot.
You manage devices by using Microsoft Intune. Automatic Intune enrollment is disabled.
Users report that they must enter the mobile device management (MDM) server address during device enrollment.
To reduce user interaction during device enrollment, you plan to create the following CNAME DNS hostname records:
1. EnterpriseEnrollment.contoso.com
2. EnterpriseRegistration.contoso.com
You need to configure a fully qualified domain name (FQDN) for each CNAME record to redirect enrollment requests to the Intune servers.
How should you configure each FQDN? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Box 1: manage.microsoft.com
EnterpriseEnrollment-s
Enable auto-discovery of Intune enrollment server
If you're not using automatic enrollment as part of your enrollment or provisioning solution, we recommend creating a domain name server (DNS) alias, called a CNAME record type, for your MDM servers. The CNAME redirects enrollment requests to Intune servers so that device users don't have to enter the server address during device enrollment. Although the CNAME configuration is optional, it makes enrollment easier for users by enabling automatic discovery of the Intune enrollment server and reducing the amount of user interaction required.
Step 1: Create CNAME
Create CNAME DNS resource records for your organization's domain. For example, if your organization's website is contoso.com, create a CNAME record in DNS that redirects EnterpriseEnrollment.contoso.com to enterpriseenrollment-s.manage.microsoft.com.
If no enrollment CNAME record is found, users are prompted to manually enter the MDM server name: enrollment.manage.microsoft.com.
Box 2: .windows.net.
EnterpriseRegistration
Use EnterpriseRegistration.company_domain.com which points to EnterpriseRegistration.windows.net.
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Microsoft exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your MD-102 exam preparations
and Microsoft certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.