10 free Microsoft MD-102 practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 409 questions. Work through them, then open each answer to check your reasoning.
Get all 409 questions (US$39) · Download these 10 as a PDF
Question 1
Show the case study this question is based on
CASE STUDY
Overview
ADatum Corporation is a consulting company that has a main office in Montreal and branch offices in Seattle and New York.
ADatum has a Microsoft 365 E5 subscription.
Environment
Network Environment
The network contains an on-premises Active Directory domain named adatum.com. The domain contains the servers shown in the following table.
ADatum has a hybrid Azure AD tenant named adatum.com.
Users and Groups
The adatum.com tenant contains the users shown in the following table.
All users are assigned a Microsoft Office 365 license and an Enterprise Mobility + Security E3 license.
Enterprise State Roaming is enabled for Group1 and GroupA.
Group1 and Group2 have a Membership type of Assigned.
Devices
ADatum has the Windows 10 devices shown in the following table.
The Windows 10 devices are joined to Azure AD and enrolled in Microsoft Intune.
The Windows 10 devices are configured as shown in the following table.
All the Azure AD joined devices have an executable file named C:AppA.exe and a folder named D:Folder1.
Microsoft Intune Configuration
Microsoft Intune has the compliance policies shown in the following table.
The Automatic Enrollment settings have the following configurations:
• MDM user scope: GroupA
• MAM user scope: GroupB
You have an Endpoint protection configuration profile that has the following Controlled folder access settings:
• Name: Protection1
• Folder protection: Enable
List of apps that have access to protected folders: C:*AppA.exe List of additional folders that need to be protected: D:Folder1 Assignments:
• Included groups: Group2, GroupB
• Windows Autopilot Configuration
ADatum has a Windows Autopilot deployment profile configured as shown in the following exhibit.
Currently, there are no devices deployed by using Windows Autopilot.
The Intune connector for Active Directory is installed on Server1.
Requirements
Planned Changes
ADatum plans to implement the following changes:
Purchase a new Windows 10 device named Device6 and enroll the device in Intune New computers will be deployed by using Windows Autopilot and will be hybrid Azure AD joined.
Deployed a network boundary configuration profile that will have the following settings:
• Name: Boundary1
• Network boundary: 192.168.1.0/24
• Scope tags: Tag1
Assignments:
Included groups:
Group1, Group2 –
Deploy two VPN configuration profiles named Connection1 and Connection2 that will have the following settings:
• Name: Connection1
• Connection name: VPN1
• Connection type: L2TP
Assignments:
Included groups: Group1, Group2, GroupA Excluded groups: —
Name: Connection2 –
Connection name: VPN2 –
Connection type: IKEv2 –
Assignments:
• Included groups: GroupA
• Excluded groups: GroupB
• Technical Requirements
ADatum must meet the following technical requirements:
Users in GroupA must be able to deploy new computers.
Administrative effort must be minimized.
Which devices are registered by using the Windows Autopilot deployment service?







Show answer and explanation
The answer and explanation for this question are in the free sample PDF.
Question 2
Show the case study this question is based on
CASE STUDY
Overview
ADatum Corporation is a consulting company that has a main office in Montreal and branch offices in Seattle and New York.
ADatum has a Microsoft 365 E5 subscription.
Environment
Network Environment
The network contains an on-premises Active Directory domain named adatum.com. The domain contains the servers shown in the following table.
ADatum has a hybrid Azure AD tenant named adatum.com.
Users and Groups
The adatum.com tenant contains the users shown in the following table.
All users are assigned a Microsoft Office 365 license and an Enterprise Mobility + Security E3 license.
Enterprise State Roaming is enabled for Group1 and GroupA.
Group1 and Group2 have a Membership type of Assigned.
Devices
ADatum has the Windows 10 devices shown in the following table.
The Windows 10 devices are joined to Azure AD and enrolled in Microsoft Intune.
The Windows 10 devices are configured as shown in the following table.
All the Azure AD joined devices have an executable file named C:AppA.exe and a folder named D:Folder1.
Microsoft Intune Configuration
Microsoft Intune has the compliance policies shown in the following table.
The Automatic Enrollment settings have the following configurations:
• MDM user scope: GroupA
• MAM user scope: GroupB
You have an Endpoint protection configuration profile that has the following Controlled folder access settings:
• Name: Protection1
• Folder protection: Enable
List of apps that have access to protected folders: C:*AppA.exe List of additional folders that need to be protected: D:Folder1 Assignments:
• Included groups: Group2, GroupB
• Windows Autopilot Configuration
ADatum has a Windows Autopilot deployment profile configured as shown in the following exhibit.
Currently, there are no devices deployed by using Windows Autopilot.
The Intune connector for Active Directory is installed on Server1.
Requirements
Planned Changes
ADatum plans to implement the following changes:
Purchase a new Windows 10 device named Device6 and enroll the device in Intune New computers will be deployed by using Windows Autopilot and will be hybrid Azure AD joined.
Deployed a network boundary configuration profile that will have the following settings:
• Name: Boundary1
• Network boundary: 192.168.1.0/24
• Scope tags: Tag1
Assignments:
Included groups:
Group1, Group2 –
Deploy two VPN configuration profiles named Connection1 and Connection2 that will have the following settings:
• Name: Connection1
• Connection name: VPN1
• Connection type: L2TP
Assignments:
Included groups: Group1, Group2, GroupA Excluded groups: —
Name: Connection2 –
Connection name: VPN2 –
Connection type: IKEv2 –
Assignments:
• Included groups: GroupA
• Excluded groups: GroupB
• Technical Requirements
ADatum must meet the following technical requirements:
Users in GroupA must be able to deploy new computers.
Administrative effort must be minimized.
You implement Boundary1 based on the planned changes.
Which devices have a network boundary of 192.168.1.0/24 applied?







Show answer and explanation
The answer and explanation for this question are in the free sample PDF.
Question 3
You have devices enrolled in Microsoft Intune as shown in the following table.
On which devices can you apply app configuration policies?

Show answer and explanation
Correct answer: C. Device3 and Device4 only
Intune app configuration policies support only iOS/iPadOS and Android apps, delivering settings to managed apps on those platforms (for enrolled devices or managed apps). Device3 runs Android and Device4 runs iOS, so both can receive them. Windows devices use device configuration profiles, settings catalog policies, or administrative templates instead, so Device1 and Device2 are not eligible.
Why the other options are wrong
- A. Device2 runs Windows 11, and app configuration policies cannot be assigned to Windows.
- B. Device1 and Device2 are Windows devices, which these policies do not support.
- D. Device2 runs Windows 11, an unsupported platform for app configuration policies.
- E. Windows 10 and Windows 11 are not supported by app configuration policies.
Question 4
You have a Microsoft 365 subscription that uses Microsoft Intune Suite.
You use Microsoft Intune to manage devices.
You plan to deploy two apps named App1 and App2 to all Windows devices. App1 must be installed before App2.
From the Intune admin center, you create and deploy two Windows app (Win32) apps.
You need to ensure that App1 is installed before App2 on every device.
What should you configure?
Show answer and explanation
Correct answer: D. the App2 deployment configurations
In Microsoft Intune, app dependency relationships are configured in the deployment settings of the dependent app. To ensure App1 is installed before App2, you must configure App2's deployment to add App1 as a dependency. This is done in the App2 deployment configurations, not in App1 or through device groups or detection rules.
Why the other options are wrong
- A. App1 deployment configurations do not define what must happen before other apps are installed; the dependent app specifies its prerequisites.
- B. A dynamic device group is used to target devices for deployment but does not control installation order or dependencies.
- C. A detection rule is used to verify whether an app is installed but does not establish installation sequencing or dependencies.
Question 5
You have a Microsoft Intune subscription.
You have devices enrolled in Intune as shown in the following table.
An app named App1 is installed on each device.
What is the minimum number of app configuration policies required to manage App1?

Show answer and explanation
Correct answer: B. 2
App configuration policies in Microsoft Intune must be created separately for each platform/OS type. The devices show two distinct platforms: Android (Device1 with Android 8.1.0 and Device2 with Android 9) and iOS (Device3 with iOS 11.4.1, Device4 with iOS 12.3.1, and Device5 with iOS 12.3.2). While there are different OS versions, app configuration policies are platform-specific, not version-specific. Therefore, a minimum of 2 policies is required: one for Android devices and one for iOS devices, regardless of the minor version differences within each platform.
Why the other options are wrong
- A. A single policy cannot target both Android and iOS devices simultaneously; platfor-pecific policies are required.
- C. Three policies would be unnecessary as iOS version differences (11.4.1, 12.3.1, 12.3.2) do not require separate policies.
- D. Four policies would treat Android versions separately, which is not required; Android policies apply across supported versions.
- E. Five policies would create one per device, which is excessive and not how Intune app configuration policies are designed to work.
Question 6
You have a Microsoft 365 E5 subscription that contains 100 iOS devices enrolled in Microsoft Intune.
You need to deploy a custom line-of-business (LOB) app to the devices by using Intune.
Which extension should you select for the app package file?
Show answer and explanation
Correct answer: B. .ipa
Intune use the .ipa (iOS App Package) file format. This is the standard package extension for iOS applications that can be deployed through Intune to enrolled iOS devices.
Why the other options are wrong
- A. .intunemac is used for macOS app packages, not iOS.
- C. .apk is the Android package format, not used for iOS devices.
- D. .appx is the Windows app package format, not applicable to iOS.
Question 7
You have a Microsoft 365 E5 subscription that contains a user named User1 and a web app named App1.
App1 must only accept modern authentication requests.
You plan to create a Conditional Access policy named CAPolicy1 that will have the following settings:
• Assignments
• Users or workload identities: User1 Cloud apps or actions: App1
• Access controls
• Grant: Block access
You need to block only legacy authentication requests to App1.
Which condition should you add to CAPolicy1?
Show answer and explanation
Correct answer: E. Client apps
To block only legacy authentication requests while allowing modern authentication, you must add a Client apps condition to the Conditional Access policy. The Client apps condition allows you to specify whether the policy applies to legacy authentication clients or modern authentication clients, enabling granular control over authentication protocols.
Why the other options are wrong
- A. Filter for devices filters based on device properties but does not distinguish between legacy and modern authentication protocols.
- B. Device platforms condition targets operating systems but does not differentiate authentication methods.
- C. User risk is based on user behavior analysis and compromised credentials, not authentication protocol type.
- D. Sign-in risk evaluates the risk of a specific sign-in event, not the authentication method being used.
Question 8
You have a Microsoft 365 subscription.
You have 10 computers that run Windows 10 and are enrolled in mobile device management (MDM).
You need to deploy the Microsoft 365 Apps for enterprise suite to all the computers.
What should you do?
Show answer and explanation
Correct answer: D. From the Microsoft Intune admin center, add an app.
To deploy Microsoft 365 Apps for enterprise to Windows 10 MDM-enrolled devices, you add an app from the Microsoft Intune admin center. This is the standard method for deploying Microsoft 365 Apps and other applications to Intune-managed devices.
Why the other options are wrong
- A. A device profile is used for configuration settings, not for deploying applications.
- B. An app registration in Azure AD is for authentication and API access, not for application deployment.
- C. An enterprise application in Azure AD is for SSO and access management, not for deploying software to devices.
Question 9
You have a Microsoft 365 subscription that uses Microsoft Intune Suite.
You use Microsoft Intune to manage devices.
You have a Windows 11 device named Device1 that is enrolled in Intune. Device1 has been offline for 30 days.
You need to remove Device1 from Intune immediately. The solution must ensure that if the device checks in again, any apps and data provisioned by Intune are removed. Use-nstalled apps, personal data, and OEM-installed apps must be retained.
What should you use?
Show answer and explanation
Correct answer: B. a Retire action
A Retire action removes a device from Intune management and removes only Intune-provisioned apps and data. When the device checks in again, Intune-managed apps and corporate data are removed, but user-installed apps, personal data, and OEM-installed apps are retained, which matches the requirement exactly.
Why the other options are wrong
- A. A Delete action removes the device record but does not clean up provisioned apps and data when the device reconnects.
- C. Fresh Start reinstalls Windows and removes apps installed on the device, so user-installed apps are not retained.
- D. Autopilot Reset is designed for device redeployment and removes all user data and apps, not just Intune-provisioned items.
Question 10
You have a Microsoft 365 subscription that uses Microsoft Intune Suite.
You use Microsoft Intune to manage devices.
You need to review the startup times and restart frequencies of the devices.
What should you use?
Show answer and explanation
Correct answer: D. Endpoint analytics
Endpoint analytics is the Microsoft Intune feature specifically designed to measure and report on device startup times and restart frequencies. It provides insights into device performance and user experience metrics.
Why the other options are wrong
- A. Azure Monitor is a general-purpose monitoring service but is not the dedicated Intune solution for device startup and restart metrics.
- B. Intune Data Warehouse is used for reporting on device management data but does not specifically focus on startup times and restart frequencies.
- C. Microsoft Defender for Endpoint provides security-focused monitoring and threat detection, not device performance metrics like startup times.
That was 10 of 409.
The full Microsoft MD-102 pack has all 409 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
