MD-102 - Protect Devices (18% of the exam) - Section 3.1

Configure endpoint security by using Microsoft Intune and Microsoft Defender for Endpoint.

Create antivirus, disk encryption, firewall and attack surface reduction policies in Intune, including BitLocker recovery key management and self-service recovery, and plan security baselines. Integrate Intune with Microsoft Defender for Endpoint, onboard devices, configure EDR policies and triage incidents, and configure App Control for Business policies.

endpoint security policiesBitLocker disk encryptionattack surface reduction rulessecurity baselinesMicrosoft Defender for Endpoint onboardingApp Control for Business

Practice question for this objective

Free sampleProtect Deviceshard

Windows 11 devices are enrolled in Microsoft Intune, the organisation holds Microsoft Defender for Endpoint licences, and the security team can sign in to the Microsoft Defender portal. No enrolled device appears in the device inventory of the Defender portal, and the endpoint security node of the Microsoft Intune admin center reports the Microsoft Defender for Endpoint connection status as unavailable. You must have the enrolled Windows devices onboarded to Microsoft Defender for Endpoint from Intune. Select TWO actions.

  • ATurn on the connection to Microsoft Intune in the advanced features of the Microsoft Defender portal, so that the service to service connection between the two services is established. Correct
  • BCreate an endpoint detection and response policy in Intune that takes its client configuration package automatically from the connector, and assign it to a group holding those Windows devices. Correct
  • CAssign a Windows compliance policy that requires the device to be at or under a stated machine risk score, so that Intune begins collecting a risk rating from Defender for Endpoint.
  • DDeploy an endpoint security antivirus policy that turns on cloud delivered protection and real time protection for the same group of enrolled Windows 11 devices.
  • ESwitch tamper protection on in the Windows security baseline, so that nothing running on the device can stop the Defender for Endpoint sensor from registering with the service.
Onboarding from Intune needs the Defender for Endpoint connection switched on and an endpoint detection and response policy that delivers the onboarding configuration. Onboarding is a configuration change rather than an agent installation. The sensor already ships in Windows, and it stays dormant until it receives onboarding configuration naming the tenant it should report to. Intune obtains that configuration through the service to service connection, so the connection has to be established first, and an endpoint detection and response policy is what then delivers it to an assigned device. Neither an antivirus policy nor a compliance policy carries that configuration.

Why A is correct: Correct. The connector is a two ended arrangement, and the Defender portal side of it has to be switched on before Intune can obtain onboarding configuration from Defender for Endpoint or receive device risk back from it.

Why B is correct: Correct. The endpoint detection and response policy is the vehicle that carries the onboarding configuration to an assigned device, and taking the package automatically from the connector avoids handling an exported onboarding file.

Why C is wrong: Tempting because that setting is genuinely part of the integration and does read a rating from Defender for Endpoint. It is wrong here because a compliance policy reports a state for a device that is already onboarded, and it onboards nothing itself.

Why D is wrong: Tempting because Microsoft Defender Antivirus and Defender for Endpoint work together on a Windows client. It is wrong because antivirus settings tune protection on a device, and the device still holds no sensor registration with the Defender for Endpoint service.

Why E is wrong: Tempting because tamper protection does defend the sensor once it is running. It is wrong because it protects settings that already exist, and a device that has never been onboarded has no sensor registration to protect.

See more MD-102 practice questions, answers explained.

Exam traps in Protect Devices

Answers that look right on this material and are not. Each one is a distractor from a different question in the MD-102 bank for this domain.

  • Reassign the attack surface reduction policy to a device group instead of a user group.

    Why it is wrong: Attack surface reduction policies can be assigned to either device or user groups, and the reported success shows the settings already reached the devices, so changing the target type addresses nothing about why the rules are not evaluated.

  • Install the Intune management extension on the machines with an onboarding script, so that the extension collects the endpoint security policies assigned to them and applies each one.

    Why it is wrong: Tempting because the management extension is what delivers several Intune payloads on Windows. It is wrong because the extension is placed on a device by enrolment and cannot be adopted by a machine that has no Intune enrolment record.

  • It is switched off entirely by the third-party installation and stops scanning, so nothing Microsoft Defender Antivirus does can be observed until the third-party product is uninstalled from the device.

    Why it is wrong: This is tempting because it describes what happens on a Windows client that has not been onboarded to Microsoft Defender for Endpoint, where the built-in engine does step aside completely. It is wrong here because onboarding changes that outcome, leaving the engine running in a reduced role rather than switched off.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.