MD-102 - Manage and Secure Applications (18% of the exam) - Section 4.1

Deploy and update apps by using Intune, including Win32, line-of-business, store and Microsoft 365 Apps.

Prepare and deploy Win32, line-of-business and Microsoft Store apps, and apps from Apple Volume Purchase Program and managed Google Play. Deploy and manage Microsoft 365 Apps through Intune, the Office Deployment Tool and the Microsoft 365 Apps admin center, including during Autopilot, configure Office app policies and Quiet Time policies, and troubleshoot failed installations.

Win32 app deploymentline-of-business appsMicrosoft 365 Apps admin centerOffice Deployment ToolApple Volume Purchase Programmanaged Google Play

Practice question for this objective

Free sampleManage and Secure Applicationsmedium

Microsoft 365 Apps for enterprise is delivered to Windows 11 devices by a Microsoft 365 Apps app in Microsoft Intune, and the same devices are also visible in the Microsoft 365 Apps admin center. A team is dividing the work between the two consoles and has to be clear about which console does what. Select TWO tasks that the Microsoft 365 Apps admin center performs for those devices.

  • AReport the Microsoft 365 Apps build that each device runs and the add-ins loaded on it, detail that the Intune app installation record does not carry. Correct
  • BEnrol a device in Microsoft Intune, because a device that reports its Office build to the admin center is registered for device management by it.
  • CTake ownership of Microsoft 365 Apps update behaviour with Cloud Update, so that builds are scheduled centrally rather than fixed by the Intune app channel. Correct
  • DAssign a Windows compliance policy so that the Office build on each device is reported as a compliance state to Conditional Access.
  • EDeliver an unrelated Win32 line-of-business application to the same devices from the packaged content that Microsoft Intune already holds.
The Microsoft 365 Apps admin center reports Office build and add-in detail and can own update servicing, while enrolment, compliance and Win32 delivery stay with Intune. The split follows what each service actually holds. Intune knows that it delivered an app and whether the installation succeeded, and it owns enrolment, compliance and every other app type. The Microsoft 365 Apps admin center receives what the click-to-run client reports about itself, which is why it can describe the running build and the add-ins loaded, and why it is the console that can take over update servicing for the suite.

Why A is correct: The admin center is built around what the Office client reports about itself, so it describes the running build and the add-ins in use, which is finer detail than the installed or failed state Intune keeps for the app it delivered.

Why B is wrong: Tempting because both consoles list the same machines, but reporting an Office build is not an enrolment, and enrolling a device remains a matter for Intune and Microsoft Entra ID.

Why C is correct: Central servicing is a capability of the admin center itself, and it moves the decision about which build a device runs away from the channel recorded when the Intune app installed the suite.

Why D is wrong: Tempting because compliance reporting also aggregates device state, but compliance policies are authored and assigned in Intune, and the admin center takes no part in the Conditional Access gate.

Why E is wrong: Tempting because both consoles deal with applications, but the admin center concerns Microsoft 365 Apps alone, and delivery of a Win32 app stays with Intune.

See more MD-102 practice questions, answers explained.

Exam traps in Manage and Secure Applications

Answers that look right on this material and are not. Each one is a distractor from a different question in the MD-102 bank for this domain.

  • The device is enrolled in Microsoft Intune and reports a compliant state against a Windows compliance policy that is assigned to it.

    Why it is wrong: Tempting because the suite was delivered by Intune in this scenario, but eligibility is read from the reporting of the Office client, and a compliance state is an input to Conditional Access rather than to servicing of the suite.

  • Package the Office Deployment Tool together with the configuration file as a Win32 app, and let that package carry the installation of the suite instead.

    Why it is wrong: Tempting because the tool does install the suite, but it abandons the Microsoft 365 Apps app type the requirement keeps, along with its channel handling and reporting, for no gain.

  • Create a Windows quality update policy in Microsoft Intune that names the current monthly update and assign it to the laptops, so that new Office builds are held back alongside the Windows content the policy governs.

    Why it is wrong: Tempting because a quality update policy does control the timing of a named release. It is wrong because such a policy governs Windows quality content, and it expedites a release rather than delaying one, so it neither reaches Office nor slows anything down.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.