8 real MD-102 flashcards, sampled from 4 of the 5 domains the exam tests, heaviest first. Where a tempting wrong answer encodes a belief people genuinely hold, the card corrects it too - the trap most decks skip. No account, no card.
The full deck has 298 flashcards, and a free account opens 40 of them across every domain. For a domain-by-domain breakdown and a study plan, read the MD-102 study guide.
schoolConceptManage and Maintain Devices
When moving Windows 10 devices to a named Windows 11 version, how is the work divided between an Intune update ring and a Windows 11 feature update policy?
arrow_downward
Version and timing are separate controls. The feature update policy is the object that names the Windows version a device is brought up to, and it keeps the device at that version rather than letting it advance. The update ring expresses when updates are allowed to arrive, so a feature update deferral or an active pause in the ring can hold back the very upgrade the policy is offering, which is a common reason an assigned policy appears to do nothing.
Common misconceptionA feature update policy does not take over quality updates. It governs the feature version alone, and the update ring remains the object that controls quality update behaviour.
schoolConceptManage and Maintain Devices
How does a classic Windows Autopilot deployment profile identify the device being provisioned, compared with a Windows Autopilot device preparation policy?
arrow_downward
The two differ at the point where device and policy meet. A deployment profile is matched to a hardware identity that already exists in the tenant, so registration is a prerequisite and an unregistered machine simply runs a normal out-of-box experience. A device preparation policy is assigned to a user group, so the policy is resolved from the account signing in, and Intune adds the machine to the device security group it owns during provisioning, which removes the registration prerequisite entirely.
Common misconceptionImporting the hardware identity is not mandatory for both approaches. A device preparation policy provisions a device that was never imported, which is the main reason the newer approach exists.
schoolConceptPrepare Infrastructure for Devices
An Intune role assignment names members, a scope (groups) and a scope tag. Which part decides the users and devices the delegated administrator may act on?
arrow_downward
The scope (groups) of an assignment is the population of users and devices the assignment reaches, so a helpdesk scoped to PerthDevices can act only on that group's members. Members and scope (groups) both name Microsoft Entra ID groups, which is why they get confused, but members says who holds the role and scope says who the role reaches.
schoolConceptPrepare Infrastructure for Devices
A regional team must create and edit compliance policies for its own country only, and must not see the policies owned by other regions. Which combination of Intune controls delivers least privilege?
arrow_downward
Two requirements need two different controls, because roles decide what an administrator can do and scope tags decide what an administrator can see. A custom Intune role built from the compliance policy permissions limits the actions, a scope (groups) of the regional devices limits the reach, and a regional scope tag on both the assignment and the policies limits the visible objects. A Microsoft Entra ID directory role satisfies neither, being tenant wide.
Common misconceptionA scope tag never grants a permission. Tagging the regional policies does make them visible to a Read Only Operator, but the role stays read only and the team still cannot create or edit anything.
schoolConceptProtect Devices
What must an Intune antivirus policy have configured for block at first sight to reach a verdict on an executable no security intelligence update has yet described?
arrow_downward
Block at first sight breaks the dependency on a locally held definition. When the engine meets a file it cannot classify, it holds access to the file and asks the cloud protection service for a verdict, submitting metadata and, where the service asks for it, the sample. That exchange is possible when cloud-delivered protection is enabled and sample submission permits the file to be sent, which is why those two settings are the dependency rather than update frequency or onboarding state.
schoolConceptProtect Devices
A Windows 11 device onboarded to Microsoft Defender for Endpoint has a third-party antivirus installed and registered as active. What happens to Microsoft Defender Antivirus?
arrow_downward
It moves into passive mode rather than a disabled state. Onboarding keeps the built-in engine loaded, so it continues to receive security intelligence updates, remains available for on-demand scanning and keeps feeding signal to Defender for Endpoint, while the third-party product owns real-time protection. Without onboarding the built-in engine would instead be disabled, so onboarding state, not the presence of the third-party product alone, decides the outcome.
Common misconceptionTwo real-time engines do not simply coexist for layered safety. Windows recognises a single registered real-time antivirus solution, and running two real-time engines against the same file operations is not the supported design.
schoolConceptManage and Secure Applications
What does the Microsoft Win32 Content Prep Tool actually produce, and what must still be defined on the app record in Intune?
arrow_downward
The tool takes a source folder and a named setup file and emits a single encrypted .intunewin container. The Intune Management Extension downloads it to the device, decrypts it, extracts it to a temporary location and runs whatever install command the app record carries. Because the package is opaque, Intune learns nothing about the application from it, so the install command, the uninstall command, the requirement rules and the detection rules all have to be stated separately when the app is created.
schoolConceptManage and Secure Applications
What is true of a device-assigned volume purchased licence for an iPad app deployed through Microsoft Intune?
arrow_downward
Volume purchased applications reach Intune through a token uploaded from Apple Business Manager, and each purchased title can be assigned by user or by device. Device assignment attaches the entitlement to the enrolled hardware, so the install proceeds without an Apple Account being present and without an invitation being accepted, which is what makes shared and kiosk iPads workable. When the application is removed from that device, the entitlement returns to the available pool for reuse elsewhere.
Common misconceptionDevice licensing does not remove the Apple Business Manager token. The token is what proves the tenant owns the purchases, and without a valid synchronised token neither licensing model can assign a volume purchased title.
Examworthy is not affiliated with or endorsed by Microsoft. All flashcards are original, drawn from our own blueprint-aligned practice questions. We never reproduce live exam items. MD-102 and related marks belong to their respective owners.