Download Endpoint Administrator.MD-102.ExamTopics.2026-04-27.388q.vcex

Vendor: Microsoft
Exam Code: MD-102
Exam Name: Endpoint Administrator
Date: Apr 27, 2026
File Size: 13 MB
Downloads: 1

How to open VCEX files?

Files with VCEX extension can be opened by ProfExam Simulator.

ProfExam Discount

Demo Questions

Question 1
You have a Microsoft 365 E5 subscription and a computer that runs Windows 11.
You need to create a customized installation of Microsoft 365 Apps for enterprise.
Which four actions should you perform in sequence? To answer, move the appropriate cmdlets from the list of cmdlets to the answer area and arrange them in the correct order.
Correct answer: To work with this question, an Exam Simulator is required.
Question 2
You have a Microsoft 365 E5 subscription that contains 100 iOS devices enrolled in Microsoft Intune.
You need to deploy a custom line-of-business (LOB) app to the devices by using Intune.
Which extension should you select for the app package file?
  1. .intunemac
  2. .ipa
  3. .apk
  4. .appx
Correct answer: B
Explanation:
B: 37 - Mosted
Question 3
You have a Microsoft 365 E5 subscription that contains a user named User1 and a web app named App1.
App1 must only accept modern authentication requests.
You plan to create a Conditional Access policy named CAPolicy1 that will have the following settings:
  • Assignments 
  • Users or workload identities: User1
  • Cloud apps or actions: App1 -
  • Access controls
  • Grant: Block access
You need to block only legacy authentication requests to App1.
Which condition should you add to CAPolicy1?
  1. Filter for devices
  2. Device platforms
  3. User risk
  4. Sign-in risk
  5. Client apps
Correct answer: E
Explanation:
E: 30 - Mosted
Question 4
You have a Microsoft 365 subscription.
You have 10 computers that run Windows 10 and are enrolled in mobile device management (MDM).
You need to deploy the Microsoft 365 Apps for enterprise suite to all the computers.
What should you do?
  1. From the Microsoft Intune admin center, create a Windows 10 device profile.
  2. From Azure AD, add an app registration.
  3. From Azure AD, add an enterprise application.
  4. From the Microsoft Intune admin center, add an app.
Correct answer: D
Explanation:
A: 2B: 1D: 76 - Mosted
Question 5
You have a Microsoft 365 subscription that uses Microsoft Intune Suite.
You use Microsoft Intune to manage devices.
You have a Windows 11 device named Device1 that is enrolled in Intune. Device1 has been offline for 30 days.
You need to remove Device1 from Intune immediately. The solution must ensure that if the device checks in again, any apps and data provisioned by Intune are removed. User-installed apps, personal data, and OEM-installed apps must be retained.
What should you use?
  1. a Delete action
  2. a Retire action
  3. a Fresh Start action
  4. an Autopilot Reset action
Correct answer: A
Explanation:
A: 77 - MostedB: 60C: 1D: 1
Question 6
You have a Microsoft 365 E5 subscription that contains 500 macOS devices enrolled in Microsoft Intune.
You need to ensure that you can apply Microsoft Defender for Endpoint antivirus policies to the macOS devices. The solution must minimize administrative effort.
What should you do?
  1. Onboard the macOS devices to the Microsoft Purview compliance portal.
  2. From the Microsoft Intune admin center, create a security baseline.
  3. Install Defender for Endpoint on the macOS devices.
  4. From the Microsoft Intune admin center, create a configuration profile.
Correct answer: D
Explanation:
C: 33D: 36 - Mosted
Question 7
Your network contains an on-premises Active Directory domain and an Azure AD tenant.
The Default Domain Policy Group Policy Object (GPO) contains the settings shown in the following table.
You need to migrate the existing Default Domain Policy GPO settings to a device configuration profile.
Which device configuration profile type template should you use?
  1. Administrative Templates
  2. Endpoint protection
  3. Device restrictions
  4. Custom
Correct answer: C
Explanation:
A: 32B: 1C: 41 - MostedD: 8
Question 8
You have a Microsoft 365 E5 subscription.
You create a new update rings policy named Policy1 as shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Correct answer: To work with this question, an Exam Simulator is required.
Question 9
You have a Microsoft 365 E5 subscription that contains 150 hybrid Azure AD joined Windows devices. All the devices are enrolled in Microsoft Intune.
You need to configure Delivery Optimization on the devices to meet the following requirements:
Allow downloads from the internet and from other computers on the local network.
Limit the percentage of used bandwidth to 50.
What should you use?
  1. a configuration profile
  2. a Windows Update for Business Group Policy setting
  3. a Microsoft Peer-to-Peer Networking Services Group Policy setting
  4. an Update ring for Windows 10 and later profile
Correct answer: A
Explanation:
A: 34 - MostedB: 1D: 1
Question 10
You have a Microsoft 365 subscription that uses Microsoft Intune Suite.
You use Microsoft Intune to manage devices.
You plan to deploy two apps named App1 and App2 to all Windows devices. App1 must be installed before App2.
From the Intune admin center, you create and deploy two Windows app (Win32) apps.
You need to ensure that App1 is installed before App2 on every device.
What should you configure?
  1. the App1 deployment configurations
  2. a dynamic device group
  3. a detection rule
  4. the App2 deployment configurations
Correct answer: D
Explanation:
A: 1D: 38 - Mosted
Question 11
Case study -
Overview -
ADatum Corporation is a consulting company that has a main office in Montreal and branch offices in Seattle and New York.
ADatum has a Microsoft 365 E5 subscription.
Environment -
Network Environment -
The network contains an on-premises Active Directory domain named adatum.com. The domain contains the servers shown in the following table.
ADatum has a hybrid Azure AD tenant named adatum.com.
Users and Groups -
The adatum.com tenant contains the users shown in the following table.
All users are assigned a Microsoft Office 365 license and an Enterprise Mobility + Security E3 license.
Enterprise State Roaming is enabled for Group1 and GroupA.
Group1 and Group2 have a Membership type of Assigned.
Devices -
ADatum has the Windows 10 devices shown in the following table.
The Windows 10 devices are joined to Azure AD and enrolled in Microsoft Intune.
The Windows 10 devices are configured as shown in the following table.
All the Azure AD joined devices have an executable file named C:\AppA.exe and a folder named D:\Folder1.
Microsoft Intune Configuration -
Microsoft Intune has the compliance policies shown in the following table.
The Automatic Enrollment settings have the following configurations:
  • MDM user scope: GroupA
  • MAM user scope: GroupB
You have an Endpoint protection configuration profile that has the following Controlled folder access settings:
  • Name: Protection1
  • Folder protection: Enable
  • List of apps that have access to protected folders: C:\*\AppA.exe
  • List of additional folders that need to be protected: D:\Folder1
Assignments:
  • Included groups: Group2, GroupB
  • Windows Autopilot Configuration
ADatum has a Windows Autopilot deployment profile configured as shown in the following exhibit.
Currently, there are no devices deployed by using Windows Autopilot.
The Intune connector for Active Directory is installed on Server1.
Requirements -
Planned Changes -
ADatum plans to implement the following changes:
Purchase a new Windows 10 device named Device6 and enroll the device in Intune
New computers will be deployed by using Windows Autopilot and will be hybrid Azure AD joined.
Deployed a network boundary configuration profile that will have the following settings:
  • Name: Boundary1
  • Network boundary: 192.168.1.0/24
  • Scope tags: Tag1
Assignments:
  • Included groups: Group1, Group2
Deploy two VPN configuration profiles named Connection1 and Connection2 that will have the following settings:
  • Name: Connection1
  • Connection name: VPN1
  • Connection type: L2TP
Assignments:
  • Included groups: Group1, Group2, GroupA
  • Excluded groups: 
    • Name: Connection2 
    • Connection name: VPN2 
    • Connection type: IKEv2 
Assignments:
  • Included groups: GroupA
  • Excluded groups: GroupB
  • Technical Requirements
ADatum must meet the following technical requirements:
Users in GroupA must be able to deploy new computers.
Administrative effort must be minimized.
You implement Boundary1 based on the planned changes.
Which devices have a network boundary of 192.168.1.0/24 applied?
  1. Device2 only
  2. Device3 only
  3. Device1, Device2, and Device5 only
  4. Device1, Device2, Device3, and Device4 only
Correct answer: D
Explanation:
B: 4D: 65 - Mosted
HOW TO OPEN VCE FILES

Use VCE Exam Simulator to open VCE files
Avanaset

HOW TO OPEN VCEX AND EXAM FILES

Use ProfExam Simulator to open VCEX and EXAM files
ProfExam Screen

ProfExam
ProfExam at a 20% markdown

You have the opportunity to purchase ProfExam at a 20% reduced price

Get Now!