MD-102 - Manage and Maintain Devices (28% of the exam) - Section 2.3

Implement Intune Suite add-on capabilities.

Configure Endpoint Privilege Management elevation policies and monitor elevated actions, manage apps from the Enterprise App Catalog, and configure Remote Help. Plan and implement Microsoft Cloud PKI for automated certificate issuance, Microsoft Tunnel for Mobile Application Management, and Intune Advanced Analytics for anomaly detection and proactive insights.

Endpoint Privilege ManagementEnterprise App CatalogRemote HelpMicrosoft Cloud PKIMicrosoft Tunnel for MAMAdvanced Analytics

Practice question for this objective

Free sampleManage and Maintain Deviceshard

An organisation holds the Intune Suite add-on capabilities and runs a Microsoft Tunnel Gateway server that reports healthy in the Microsoft Intune admin center. Contractors use personally owned iPhones that the organisation has agreed will stay unenrolled, and the work applications on those handsets must reach an internal web application through the tunnel. Select TWO actions that deliver the tunnel client and its connection settings to those handsets.

  • ADeploy the Microsoft Defender for Endpoint application to the contractor group as the tunnel client that the handsets will use. Correct
  • BCreate an iOS/iPadOS VPN device configuration profile that names the tunnel site, enables per-app VPN and is assigned to the contractor group.
  • CCreate an app configuration policy for managed applications that carries the tunnel connection settings, assigned to the contractor group. Correct
  • DCreate an iOS compliance policy that requires the tunnel client application, assigned to the contractor group so the handsets report a tunnel state.
  • ECreate an enrolment restriction that permits personally owned iOS devices, assigned to the contractor group so the handsets can obtain the tunnel.
Microsoft Tunnel for Mobile Application Management reaches unenrolled handsets through a client application and an app configuration policy, not through device configuration. An unenrolled handset has no mobile device management channel, so nothing delivered as a device configuration profile can reach it. Microsoft Tunnel for Mobile Application Management works around that by putting the tunnel client inside an application the user installs and signs into, and by supplying the connection details through an app configuration policy scoped to managed applications, which travels over the application protection channel instead.

Why A is correct: Microsoft Tunnel for Mobile Application Management carries traffic through the Microsoft Defender for Endpoint application acting as the tunnel client, so that application has to reach the handsets before any connection is possible.

Why B is wrong: This is how an enrolled iPhone is given a tunnel connection, which makes it tempting, but a device configuration profile is delivered over the mobile device management channel and an unenrolled handset has no such channel to receive it.

Why C is correct: An app configuration policy targeted at managed applications is delivered through the application protection channel rather than through enrolment, so it is the surface that supplies the tunnel site and server details to the client application on an unenrolled handset.

Why D is wrong: A compliance policy is attractive because it appears to make the client mandatory, but a compliance policy evaluates and reports a state on enrolled devices and configures nothing, so it neither installs the client nor supplies connection settings.

Why E is wrong: An enrolment restriction sounds relevant because it governs personally owned Apple devices, but it decides which devices are allowed to enrol at all and the requirement here is to leave the handsets unenrolled.

See more MD-102 practice questions, answers explained.

Exam traps in Manage and Maintain Devices

Answers that look right on this material and are not. Each one is a distractor from a different question in the MD-102 bank for this domain.

  • The SCEP profile was assigned to a user group, and Microsoft Cloud PKI issues only device certificates, so the remedy is to reassign that same certificate profile to a device group holding the contractor laptops.

    Why it is wrong: It sounds like a familiar targeting mistake, but Cloud PKI supports certificate profiles carrying either a user or a device subject, so the assignment target is not what stopped issuance here.

  • Create a Microsoft Cloud PKI root certification authority and an issuing certification authority, then assign a PKCS certificate profile that names the issuing certification authority to the device groups.

    Why it is wrong: PKCS profiles are a genuine Intune certificate profile type, which makes this tempting, but a PKCS profile depends on a certification authority reached through the Intune Certificate Connector, and Microsoft Cloud PKI issues through the SCEP profile type instead.

  • Unassigning the SCEP certificate profile from the group that holds the laptop removes the issued certificate from the Microsoft Cloud PKI issuing certification authority, and that certificate then disappears from the issued certificate list held for the issuing certification authority.

    Why it is wrong: Removing an assignment does drive clean up of the profile, but a certificate already issued is a signed object that cannot be recalled by deletion, and an absent list entry would be no evidence at all.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.