MD-102 Notes

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/61

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 10:01 PM on 4/18/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

62 Terms

1
New cards

What is Azure AD (Entra ID)?

Cloud-based identity and access management service.

2
New cards

What is Azure AD Joined device?

Device joined directly to cloud directory only.

3
New cards

What is Hybrid Azure AD Joined?

Device joined to on-prem AD and synced to Azure AD.

4
New cards

What is Azure AD Registered?

Personal/BYOD device registered but not fully joined.

5
New cards

When use Hybrid Join?

When organization still uses on-prem AD.

6
New cards

What is MDM?

Mobile Device Management (device-level control).

7
New cards

What is MAM?

Mobile Application Management (app-level control without full device control).

8
New cards

What is automatic enrollment?

Devices enroll into Intune automatically when joined to Azure AD.

9
New cards

What is BYOD?

Bring Your Own Device (personal device used for work).

10
New cards

Corporate vs BYOD difference?

Corporate = full control, BYOD = limited control.

11
New cards

What is Windows Autopilot?

Cloud-based device deployment without imaging.

12
New cards

Main goal of Autopilot?

Zero-touch provisioning.

13
New cards

What is required for Autopilot?

Device hardware hash registered in Intune.

14
New cards

Autopilot user-driven mode?

User logs in and completes setup.

15
New cards

Autopilot self-deploying mode?

Fully automated deployment with no user input.

16
New cards

Autopilot pre-provisioned?

IT preloads apps/policies before user receives device.

17
New cards

What does Autopilot configure?

Azure AD join, Intune enrollment, apps, policies.

18
New cards

Autopilot vs imaging?

Autopilot is cloud-based, imaging is traditional/manual.

19
New cards

User group vs device group?

User group targets users, device group targets devices.

20
New cards

What is a configuration profile?

Policy that applies settings to devices.

21
New cards

Settings catalog?

Central location for configuring device settings in Intune.

22
New cards

What causes policy not applying?

Wrong group, device not enrolled, license missing, conflicts.

23
New cards

What is device check-in?

Device syncing with Intune to receive policies.

24
New cards

What are scope tags?

Used to control visibility of resources in Intune.

25
New cards

What is a compliance policy?

Rules that determine if a device is secure.

26
New cards

Examples of compliance settings?

BitLocker, password, OS version.

27
New cards

What happens if device is non-compliant?

Marked non-compliant in Intune.

28
New cards

Does compliance block access by itself?

No, requires Conditional Access.

29
New cards

Compliance + Conditional Access?

Enforces access restrictions.

30
New cards

What is Conditional Access?

Policy that controls access based on conditions.

31
New cards

Conditions in CA?

User, device, location, risk.

32
New cards

Controls in CA?

Allow, block, require MFA, require compliant device.

33
New cards

Main goal of CA?

Enforce Zero Trust security.

34
New cards

Example CA scenario?

Block access if device is non-compliant.

35
New cards

What is a Win32 app?

Advanced app deployment (.intunewin format).

36
New cards

What is LOB app?

Line-of-business app, simpler deployment.

37
New cards

Required app?

Installs automatically.

38
New cards

Available app?

User installs from Company Portal.

39
New cards

What is detection rule?

Determines if app is already installed.

40
New cards

First troubleshooting step?

Check Intune device/app install status.

41
New cards

Where to check failures?

Intune portal and device logs.

42
New cards

What are Update Rings?

Policies controlling Windows update deployment.

43
New cards

What can Update Rings control?

Deferrals, deadlines, restart behavior.

44
New cards

What is Feature Update?

Upgrade to new Windows version.

45
New cards

Purpose of Update Rings?

Controlled rollout of updates.

46
New cards

What is BitLocker?

Disk encryption for data protection.

47
New cards

Where are BitLocker keys stored?

Azure AD / Intune.

48
New cards

Why use BitLocker?

Protect data on lost/stolen devices.

49
New cards

What is Endpoint Security in Intune?

Security policies like antivirus, firewall.

50
New cards

What is Microsoft Defender?

Built-in antivirus solution.

51
New cards

What is RBAC?

Role-Based Access Control.

52
New cards

Purpose of RBAC?

Limit access based on role.

53
New cards

What are Intune roles?

Permissions assigned to admins.

54
New cards

Why use scope tags?

Restrict admin visibility.

55
New cards

What is Endpoint Analytics?

Provides performance and usage insights.

56
New cards

What can you monitor in Intune?

Compliance, apps, device health.

57
New cards

What is device status report?

Shows device configuration and compliance state.

58
New cards

Device not receiving policy—first step?

Check group assignment.

59
New cards

App not installing—first step?

Check Intune install status.

60
New cards

User blocked from access—why?

Likely Conditional Access policy.

61
New cards

Device non-compliant—impact?

Access blocked if CA enforced.

62
New cards

Policy conflict—result?

One policy overrides or fails.