MD-102 - Prepare Infrastructure for Devices (23% of the exam) - Section 1.2

Enroll devices to Microsoft Intune across Windows, Apple and Android platforms.

Configure Intune enrollment settings and restrictions, automatic enrollment for Windows, and personal enrollment for macOS, iOS and iPadOS. Configure corporate Apple enrollment through Apple Business Manager, Android enrollment profiles (fully managed, dedicated, corporate-owned work profile, personal work profile) and zero-touch options through Samsung Knox Mobile Enrollment or Google Zero Touch, and troubleshoot enrollment failures.

Windows automatic enrollmentenrollment restrictionsApple Business ManagerAndroid Enterprise enrollment profilesSamsung Knox Mobile EnrollmentGoogle Zero Touch

Practice question for this objective

Free samplePrepare Infrastructure for Deviceshard

Your organisation registers new Samsung handsets in Samsung Knox Mobile Enrollment and registers handsets from a second vendor in the Google zero touch portal. Both sets are to be managed by Microsoft Intune as corporate owned Android Enterprise devices. Which statement describes what those two registration services contribute to the enrolment?

  • AEach service enrols the handset in Microsoft Intune on its own, and the Intune enrolment profile decides only which Android Enterprise management mode the handset is placed in after enrolment finishes.
  • BEach service takes the place of the Managed Google Play connection, so a tenant using either of them enrols corporate owned handsets without any link between Intune and Managed Google Play.
  • CEach service registers the handset with Microsoft Entra ID before first boot, so the handset arrives Microsoft Entra joined and then reaches Intune through automatic enrolment.
  • DEach service delivers a management configuration to the handset during its initial setup, and the Intune enrolment profile token carried inside that configuration is what drives the handset into Intune. Correct
Knox Mobile Enrollment and zero touch provision a management configuration at setup; the Intune enrolment profile token inside it points the device at your tenant. Both services are out of box provisioning channels owned by Samsung and Google respectively, not management services. Each pushes a configuration that names the device policy controller and carries the enrolment token generated by an Intune corporate owned enrolment profile, and the handset then contacts Intune with that token. Take the token away and the registration by itself enrols the device nowhere.

Why A is wrong: Tempting because the user experience looks like the registration service doing everything unaided. Neither service holds a relationship with your tenant by itself, so without the enrolment profile token in its configuration the handset has no way to find Intune.

Why B is wrong: Tempting because both services do remove manual steps from provisioning. The Managed Google Play connection is what establishes Android Enterprise management for the tenant, and it remains a prerequisite regardless of how a handset is registered.

Why C is wrong: Tempting because it mirrors the Windows provisioning story a candidate already knows. Microsoft Entra join and automatic enrolment through the mobile device management user scope are Windows mechanisms, and an Android device uses neither.

Why D is correct: Correct. Both services are provisioning channels: the administrator places the Intune enrolment profile token in the Knox or zero touch configuration, and the handset uses it to reach Intune during out of box setup.

See more MD-102 practice questions, answers explained.

Exam traps in Prepare Infrastructure for Devices

Answers that look right on this material and are not. Each one is a distractor from a different question in the MD-102 bank for this domain.

  • A compliance policy for the Android device administrator platform that reports a handset enrolled that way as noncompliant as soon as it first checks in.

    Why it is wrong: Tempting because it names the right platform and would flag the handsets. It is wrong because a compliance policy is evaluated after enrolment and only reports a state, so the enrolment still completes, and it would also mark the twelve handsets awaiting replacement as noncompliant.

  • Add an assignment filter to AND-Baseline that includes personally owned work profile devices so the existing policy evaluates them.

    Why it is wrong: Filters are attractive here because they do select on device properties such as ownership, but a filter only narrows an assignment that the policy already applies to. It cannot extend a policy to a profile type the policy was not created for.

  • The profile takes effect once the handsets' IMEI numbers are uploaded to Intune as corporate device identifiers, which binds each handset to that enrolment profile.

    Why it is wrong: Tempting because uploading identifiers is a real preparation step for corporate handsets. It is wrong because a corporate device identifier only lets Intune record the handset as corporate owned when it enrols; it selects no enrolment profile and creates no binding to one.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.