MD-102 domain - 18% of the exam

Protect Devices

Protect Devices is 18% of the Microsoft 365 Certified: Endpoint Administrator Associate (MD-102) exam. These are the objectives it covers, each with practice questions, with every answer explained.

Objectives in this domain

Sample question from this domain

Free sampleProtect Deviceshard

A Windows 11 device is enrolled in Microsoft Intune and is already onboarded to Microsoft Defender for Endpoint. A third-party antivirus product is then installed on it and registers itself with Windows as the active antivirus solution. Which statement correctly describes the resulting state of Microsoft Defender Antivirus on that device?

  • AIt moves into passive mode, so real-time protection is handed to the third-party product while the built-in engine keeps receiving security intelligence updates, can still run on-demand scans, and reports what it sees to Defender for Endpoint. Correct
  • BIt is switched off entirely by the third-party installation and stops scanning, so nothing Microsoft Defender Antivirus does can be observed until the third-party product is uninstalled from the device.
  • CIt remains the active antivirus solution alongside the third-party product, so two real-time engines inspect the same file operations and the device is protected by both engines at once.
  • DIt is uninstalled from the device by Windows as soon as another antivirus product registers, and it can be brought back solely by rebuilding the device or by repairing the operating system image.
Recognise that a third-party antivirus places Microsoft Defender Antivirus into passive mode on a Windows client onboarded to Microsoft Defender for Endpoint, not into a disabled state. The mode Microsoft Defender Antivirus falls into when another product registers as the active antivirus depends on whether the device is onboarded to Microsoft Defender for Endpoint. Onboarding keeps the built-in engine loaded in passive mode, so it continues to update, remains available for on-demand scanning and keeps feeding signal to the service, while the third-party product owns real-time protection. Without onboarding the built-in engine would instead be disabled, which is why the onboarding state, and not the presence of the third-party product alone, decides the answer.

Why A is correct: Correct. On a Windows client that is onboarded to Microsoft Defender for Endpoint, installing a third-party antivirus places Microsoft Defender Antivirus in passive mode rather than disabling it, which preserves updates, on-demand scanning and reporting while the third-party product owns real-time protection.

Why B is wrong: This is tempting because it describes what happens on a Windows client that has not been onboarded to Microsoft Defender for Endpoint, where the built-in engine does step aside completely. It is wrong here because onboarding changes that outcome, leaving the engine running in a reduced role rather than switched off.

Why C is wrong: This is tempting because layered protection sounds safer and administrators often assume both engines simply coexist. It is wrong because Windows recognises a single registered real-time antivirus solution, and running two real-time engines against the same file operations is not the supported design.

Why D is wrong: This is tempting because third-party security products often insist that competing agents be removed before installation. It is wrong because Microsoft Defender Antivirus is a built-in platform component that is not uninstalled when another product registers; its mode changes instead.

Other domains in this exam

See also the MD-102 cert hub, the study guide, and the cheat sheet.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.