1/19
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced |
|---|
No study sessions yet.
As the systems administrator for a company that uses Azure AD and Microsoft Intune to manage their corporate-owned mobile devices, you want to be able to access your Intune data to view reports and charts related to:
. Devices
. Enrollments
. App protection policies
. Compliance policies
. Device configuration policies
Which tool does Microsoft Intune provide to view these types of reports?
Microsoft Power BI Online reports
You're the systems administrator for an international trading company that uses Azure Active Directory (AD) and Microsoft Intune to manage their mobile devices. All company-owned mobile devices are registered in Azure AD and enrolled in Microsoft Intune.
You've created the following dynamic user groups to manage access to company resources:
. Managers: jobTitle = "Manager"
. Consultants: jobTitle = "Customer Consultant"
. OfficeAdmin: jobTitle = "Office Administrator"
. SalesReps: jobTitle = "Sales Representative"
You've created a conditional access policy that:
. Includes the SalesReps and Consultants user groups.
. Excludes the Managers user group.
. Applies the policy to the Microsoft 365, Microsoft Teams, and SharePoint cloud apps.
. Assigns the policy to Windows platforms.
. Requires that the Windows devices be marked as Compliant.
. Has a Location condition assigned to a Blocked Countries named location that blocks access from several countries based on IPv4 address.
. Is enabled.
In addition, there is a device compliance policy that requires BitLocker to be installed and running on a Windows 11 device for the device to be marked as Compliant.
After deploying the conditional access policy, you receive a support call from a customer consultant out in the field. She states that she's unable to access Microsoft Teams to join an important meeting. She's using a Windows 11 mobile device that's marked as Compliant in Intune.
You ask the consultant where she's located. She's in an airport in a country that's blocked by the named location. You inform her that she'll need to call into the Teams meeting using her cell phone.
Does this action resolve the device compliance policy issue?
Yes
You're the systems administrator for an international trading company that uses Azure Active Directory (AD) and Microsoft Intune to manage their mobile devices. All company-owned mobile devices are registered in Azure AD and enrolled in Microsoft Intune.
Many company-owned laptops are currently running Windows 10 and are enrolled in Microsoft Intune. You want to identify which of these laptops can be upgraded to Windows 11.
You create a device compliance policy and assign the policy to the laptops. After 24 hours, you view the device compliance report in Intune.
Does this solution help you identify which laptops can be upgraded?
No
You're the systems administrator for an international sports equipment retail company. The company requires that the Windows 11 laptops for employees be replaced with new Windows 11 laptops every 3 years.
In addition, the company requires the following:
. When the employees log into their new laptops, all the existing user and application settings need to be in place.
. There must be a separation of corporate and employee data.
. Data must be automatically encrypted with Azure Rights Management.
Which of the following features would BEST meet the company's requirements?
Enterprise State Roaming
You're the systems administrator for an international trading company that uses Azure Active Directory (AD) and Microsoft Intune to manage their mobile devices. All company-owned mobile devices are registered in Azure AD and enrolled in Microsoft Intune.
You've created the following dynamic user groups to manage access to company resources:
. Managers: jobTitle = "Manager"
. Consultants: jobTitle = "Customer Consultant"
. OfficeAdmin: jobTitle = "Office Administrator"
. SalesReps: jobTitle ="Sales Representative"
You've also created a device compliance policy that:
. Sends an email notification to an employee (and you) to indicate that a device is non-compliant.
. Is assigned to All Groups, with the exception of users in the OfficeAdmin group.
After deploying the device compliance policy, you notice that a Windows 11 device for a Sales Representative isn't listed as a compliant device.
You check with the Sales Representative and find out that she has just been hired for that position after working as an Office Administrator. You change the OfficeAdmin group from a dynamic group to a static group and make sure that the Sales Representative is included in the OfficeAdmin group.
Does this action resolve the device compliance policy issue?
No
You're the systems administrator for a fashion design company that uses Azure Active Directory (AD) and Microsoft Intune to manage their mobile devices. All company-owned mobile devices are registered in Azure AD and enrolled in Microsoft Intune.
You've created the following Azure AD device groups:
. Win11dev: All company-owned Windows 11 mobile devices
. iPadProdev: All company-owned iPad Pro tablets
. Androiddev: All company-owned Android mobile devices
You've created a Microsoft App Store device configuration profile that restricts several options for employee management of apps in the Microsoft Store. These setting apply on the employees' managed Windows 11 mobile devices.
However, when you test the device profile on a limited number of the Windows 11 mobile devices, you find that the device profile configurations aren't being applied.
You check the assignments for the device profile and notice that there are no assignments currently configured. On the Include tab, you assign the Win11dev device group to the device profile.
Does this action solve the issue of the unapplied device configuration profile?
Yes
You're a systems administrator for an international trading company that uses Azure Active Directory (AD) and Microsoft Intune to manage their mobile devices. All company-owned mobile devices are registered in Azure AD and enrolled in Microsoft Intune.
You've created your first device compliance policy that:
. Marks a device enrolled in Intune as Not Compliant if BitLocker isn't installed and running on a managed Windows 11 device.
. Sends an email notification to you to indicate that the device is non-compliant.
. Is assigned to a Test device group.
. The Test device group includes several new Windows 11 devices.
After deploying the device compliance policy to the Test devices group, you receive an email notification for each test device that indicates that the device is Not Compliant. You've installed BitLocker on all the test devices, and the software is running on them.
What is the MOST likely reason for the Windows 11 test devices being marked as Not Compliant?
You haven't enrolled the devices in Intune.
A user contacts you to let you know their Intune-enrolled device has been remotely locked. What would have caused this?
The user's device is non-compliant and was remotely locked.
You're the systems administrator for an international sports equipment retail company that uses Azure Active Directory (AD) and Microsoft Intune to manage their mobile devices. All company-owned Windows 11 mobile devices are registered in Azure AD and enrolled in Microsoft Intune.
You decide that you want to create an Intune conditional access policy that:
. Applies the policy to the Office 365, Microsoft Teams, and SharePoint cloud apps.
. Assigns the policy to Windows platforms.
. Requires the Windows 11 devices to be marked as Compliant.
To properly configure this Intune conditional access policy, you need to perform several tasks. From the list of tasks on the left, drag the tasks to the right in the proper order for creating the policy. (Not all listed tasks are part of creating the policy.)
Give the policy a name.
Assign users and user groups.
Select cloud apps or user actions.
Select conditions.
Grant or block access based on controls.
Enable the policy.
You're the systems administrator for an international sports equipment retail company that uses Azure Active Directory (AD) and Microsoft Intune to their manage mobile devices. All company-owned mobile devices are registered in Azure AD, enrolled in Microsoft Intune, and have BitLocker installed and running.
You've created a conditional access policy that:
. Includes an assigned Test user group.
. Applies the policy to the Microsoft 365, Microsoft Teams, and SharePoint cloud apps.
. Assigns the policy to Windows platforms.
. Requires the Windows device to be marked as Compliant.
In addition, there's a device compliance policy that requires BitLocker to be installed and running on a Windows 11 device for the device to be marked as Compliant.
After deploying the conditional access policy, you find that the policy isn't being applied to the user accounts in your Test user group.
You check the conditional access policy settings and discover that the Enable policy setting is set to Off. You change the setting to On.
Does this action resolve the compliance policy issue?
Yes
All of your company's and employees' BYOD Windows, iOS and Android devices are currently enrolled in Microsoft Intune. You want to implement an Intune feature that can do the following:
Help you manage on-premises resources for users who work remotely using Windows and Android devices.
Encrypt and protect the connection between the device and the on-premises resources.
Manage access to web applications, internal websites, and file shares through a single control plane in the Intune console.
Will Microsoft Tunnel for Intune meet your implementation requirements?
No
Which of the following are device platforms supported by Microsoft Tunnel for Intune? (Select two.)
Android
iOS/ipadOS
Which of the following tools allows you to deploy and manage devices supported by Microsoft Tunnel?
Select the correct answer from the dropdown list.
Microsoft Endpoint Manager
Which of the following platforms does not work with custom Intune device configuration profiles?
Windows 8.1
You have configured the default Intune Wi-Fi device profile. You want to make sure that the profile applies to specific users no matter which device or platform they log into.
Which of the following should you do to meet your requirements?
Assign the profile to a user group.
You are creating an Intune device configuration profile that you want to assign to the HumanResourcesAll group.
However, you want to prevent the profile from applying to a small number of training personnel who are included in the group.
Which of the following would BEST meet your configuration needs?
Use Exclusion
You have created a custom Storage Limits device profile for the laptops on the manufacturing floor of your company.
You want to make sure that the profile applies to those laptops and all users on those laptops.
Which of the following should you do to meet your requirements?
Assign the profile to a device group.
Which of the following are recommended device configurations before implementing Windows Kiosk mode? (Select three.)
Hide update notifications.
Enable logging.
Disable the hardware power button.
You have decided to use Windows PowerShell to set up a device in Windows Kiosk mode.
From the dropdown list, select the command you need to use to configure the device for Kiosk mode.
Set-AssignedAccess
You are setting up a device for Windows Kiosk mode using Microsoft Intune.
Which of the following Kiosk mode settings are available to configure the device? (Select three.)
Not configured
Multi-app kiosk
Single-app, full-screen kiosk