MD-102 - Manage and Maintain Devices (28% of the exam) - Section 2.1

Deploy and upgrade Windows clients by using cloud-based tools, including Windows Autopilot and Windows 365.

Choose between Windows Autopilot deployment profiles and Autopilot device preparation policies, and between the user-driven, pre-provisioning and self-deploying modes. Apply a device name template, configure the Enrollment Status Page, plan Windows 11 upgrades through Intune, provision Windows 365 Cloud PCs with provisioning policies, network connections and images, and implement Windows Backup and Restore.

Windows Autopilot deployment profilesAutopilot device preparationpre-provisioningEnrollment Status PageWindows 365 provisioning policiesWindows Backup and Restore

Practice question for this objective

Free sampleManage and Maintain Deviceshard

Twenty shared display computers for reception areas will be provisioned with Windows Autopilot self-deploying mode, and nobody signs in at any of them during provisioning. A signage application and a management agent must both be installed before a display reaches the desktop, and the Enrollment Status Page has to hold provisioning open until they are. An administrator has assigned the Enrollment Status Page profile and both applications to a Microsoft Entra group holding the reception staff accounts. Provisioning finishes within minutes and neither application is present. Select TWO changes that make the gating work.

  • AAssign the Enrollment Status Page profile to a Microsoft Entra group that holds the device objects of the displays. Correct
  • BAssign both applications as required to a Microsoft Entra group that holds the device objects of the displays. Correct
  • CAssign both applications as available to the reception staff so they install at the first interactive sign in.
  • DAdd a second Enrollment Status Page profile for the reception staff and give it a lower priority number.
  • ESet Only show page to devices provisioned by out-of-box experience to No in the profile that is assigned.
Know that self-deploying provisioning runs without a user, so the Enrollment Status Page profile and the apps that gate it must be targeted at device objects. Self-deploying mode completes provisioning with no user token, so the account setup phase does not run and every assignment aimed at user accounts is passed over. Both the Enrollment Status Page profile and the applications meant to hold provisioning open have to be targeted at the device objects, with the applications carrying the required intent so the device setup phase waits on them.

Why A is correct: Correct. Self-deploying provisioning runs with no user signed in, so a profile targeted at user accounts is never evaluated and the profile has to reach the device objects instead.

Why B is correct: Correct. With nobody signing in, the device setup phase is the phase that runs, and it tracks required apps targeted at the device, so both applications need a required assignment on that device group.

Why C is wrong: An available assignment depends on somebody signing in and choosing the app in the Company Portal, which is precisely what an unattended shared display in a reception area does not provide.

Why D is wrong: Priority decides which of several profiles governs a device that is in scope of more than one, so a further profile aimed at staff accounts still leaves the displays without one during provisioning.

Why E is wrong: That setting widens the enrolment paths on which the page is displayed, and these displays are already provisioned through the out-of-box experience, so it addresses nothing about the failure described.

See more MD-102 practice questions, answers explained.

Exam traps in Manage and Maintain Devices

Answers that look right on this material and are not. Each one is a distractor from a different question in the MD-102 bank for this domain.

  • Both approaches require the device hardware identity to be imported into the tenant list of Autopilot devices first, and both then deliver their settings to that device during the out-of-box experience.

    Why it is wrong: It is tempting because hardware identity import is the step most administrators associate with Autopilot, and it is genuinely mandatory for a classic deployment profile. It is wrong because a device preparation policy provisions a device that was never imported, which is the main reason the newer approach exists.

  • Provisioning stops with a naming error on each laptop, because a template that can expand past the Windows computer name limit is rejected at apply time; shortening the prefix to PER- lets provisioning continue.

    Why it is wrong: It is tempting because the template clearly expands past the limit and a hard failure feels like the safe design, but Autopilot does not fail provisioning for this; the name is shortened to fit and the device carries on.

  • Set the device name template in the Autopilot deployment profile to SYD-%SERIAL%, because the template is evaluated locally before the device ever contacts a domain controller for the join.

    Why it is wrong: Tempting because the same profile page is where naming is set for Microsoft Entra joined devices, but the template is not the naming mechanism for a hybrid join, where the domain join configuration owns the computer name.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.