MD-102 - Manage and Maintain Devices (28% of the exam) - Section 2.4

Perform remote actions on devices, including bulk actions, device queries and diagnostics collection.

Sync, restart, retire or wipe devices, individually or as a bulk action, and distinguish the data each of retire and wipe removes. Update Microsoft Defender Antivirus security intelligence, rotate BitLocker recovery keys and local administrator passwords, run a device query by using KQL, and collect diagnostics and logs, including through the Troubleshooting blade.

retire versus wipebulk device actionsdevice query with KQLBitLocker key rotationcollect diagnosticsTroubleshooting blade

Practice question for this objective

Free sampleManage and Maintain Devicesmedium

Windows 11 laptops in your tenant are Microsoft Entra joined, enrolled in Microsoft Intune and encrypted with BitLocker by a disk encryption policy that escrows the recovery password to Microsoft Entra ID. A security review requires that any recovery password read out to a user during a support call is replaced afterwards by the service desk, using the BitLocker key rotation remote action in the Microsoft Intune admin center. On a test laptop that action does not produce a new recovery password. Which prerequisite has to be in place before that remote action can rotate the key?

  • AThe operating system drive has to be decrypted and then encrypted again by the disk encryption policy, because a recovery password can be replaced only while encryption is being applied to the drive.
  • BThe service desk account has to hold the Intune Administrator role, because replacing a recovery password is reserved for tenant wide administrators rather than for a scoped role carrying device remote action permissions.
  • CA disk encryption policy has to enable client driven recovery password rotation for the join type these laptops hold, because the BitLocker client on the device is what generates and escrows the replacement password. Correct
  • DA compliance policy that requires BitLocker has to be assigned to the laptops, because Intune issues a rotation request only against a device that a compliance policy currently reports as being in a compliant state.
The BitLocker key rotation remote action depends on a disk encryption policy that enables client driven recovery password rotation for the device's join type. Intune does not mint a recovery password in the service. The remote action sends a request that the BitLocker client on the device carries out, generating a new recovery password locally and escrowing it to Microsoft Entra ID. The client only honours that request when a disk encryption policy has switched on client driven recovery password rotation covering the join type the device holds, so without that setting the action leaves the existing password in place.

Why A is wrong: It is tempting because a fresh recovery password is indeed generated when a drive is first encrypted, but rotation is a live operation on an already encrypted drive and decrypting the volume would remove the protection the review depends on.

Why B is wrong: It is tempting because recovery key work is sensitive and feels like a tenant wide privilege, but the remote action is governed by ordinary Intune role permissions on devices, so a scoped role that carries them can issue it.

Why C is correct: Correct, because the remote action only asks the BitLocker client to rotate, and the client acts on that request when policy has enabled client driven recovery password rotation for the device's join type.

Why D is wrong: It is tempting because compliance policies commonly appear alongside disk encryption work, but a compliance policy reports a state and never gates a remote action, so its presence or absence changes nothing about rotation.

See more MD-102 practice questions, answers explained.

Exam traps in Manage and Maintain Devices

Answers that look right on this material and are not. Each one is a distractor from a different question in the MD-102 bank for this domain.

  • Run the Quick scan remote action against the device, because the scan examines the common malware locations and brings the client's security intelligence up to the current release as part of that pass.

    Why it is wrong: Tempting because a scan can be made to look for a security intelligence update before it starts, but that behaviour is a setting in the antivirus policy rather than something the scan action guarantees, and the purpose of the action is to scan rather than to update.

  • The requirement is met, because the remote action installs the security intelligence, the platform and the engine together as a single package whenever a newer platform release is available for a device.

    Why it is wrong: Tempting because the three components are reported together in the Defender status on a device, but they ship and update separately, and the remote action carries no platform or engine build.

  • Reissue the same remote action as a bulk device action against the whole selection, because a bulk action is delivered by the service itself and so does not depend on the path an individual client uses to obtain content.

    Why it is wrong: Tempting because a bulk action is the efficient way to reach many devices at once, but a bulk action sends the same instruction to each client and the client still downloads from its own configured source, so the blocked path is unchanged.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.