MS 101 - Topic 1

Ace your homework & exams now with Quizwiz!

Your company has a Microsoft 365 tenant. You plan to allow users that are members of a group named Engineering to enroll their mobile device in mobile device management (MDM).The device type restrictions are configured as shown in the following table.

15 & Android Only

Your company has a Microsoft 365 subscription. The subscription contains 500 devices that run Windows 10 and 100 devices that run iOS. You need to create Microsoft Endpoint Manager device configuration profiles to meet the following requirements: ✑ Configure Wi-Fi connectivity to a secured network named ContosoNet. ✑ Require passwords of at least six characters to lock the devices. What is the minimum number of device configuration profiles that you should create?

2

HOTSPOT -You have an Azure subscription and an on-premises Active Directory domain. The domain contains 50 computers that run Windows 10.You need to centrally monitor System log events from the computers. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Hot Area:

Add and configure Azure Log Analytics workspace - Install MS Monitoring Agent

You have a Microsoft 365 tenant that is signed up for Microsoft Store for Business and contains a user named User1.You need to ensure that User1 can perform the following tasks in Microsoft Store for Business:✑ Assign licenses to users.✑ Procure apps from Microsoft Store.✑ Manage private store availability for all items. The solution must use the principle of least privilege. Which Microsoft Store for Business role should you assign to User1?

Admin

You have a Microsoft 365 tenant that contains 1,000 iOS devices enrolled in Microsoft Intune. You plan to purchase volume-purchased apps and deploy the apps to the devices. You need to track used licenses and manage the apps by using Intune. What should you use to purchase the apps?

Apple Business Manager

You have a Microsoft 365 E5 tenant. You plan to deploy 1,000 new iOS devices to users. The devices will be shipped directly from the supplier to the users. You need to recommend a Microsoft Intune enrollment option that meets the following requirements:✑ Minimizes user interaction✑ Minimizes administrative effort✑ Automatically installs corporate apps What should you recommend?

Automated Device Enrollment (ADE)

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an on-premises Active Directory domain. The domain contains 2,000 computers that run Windows 8.1 and have applications installed as shown in the following table. You enroll all the computers in Upgrade Readiness. You need to ensure that App1 and App2 have an UpgradeDecision status of Ready to upgrade. Solution: You set the Importance status of App1 to Business critical. Does this meet the goal?

B

Your company has a Microsoft 365 subscription that contains the domains shown in the following table. The company plans to add a custom domain named fabrikam.com to the subscription, and then to enable enrollment of devices to Endpoint Manager by using auto-discovery for fabrikam.com.You need to add a DNS record to the fabrikam.com domain to enable device enrollment by using auto-discovery. Which record type should you use for the new record?

CNAME

DRAG DROP -You have a Microsoft 365 E5 tenant that contains 500 Android devices enrolled in Microsoft Intune. You need to use Microsoft Endpoint Manager to deploy a managed Google Play app to the devices. Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. Select and Place:

Create Google Account - Link the account to InTune - Add the App - Assign the app

Your company has a Microsoft 365 E5 subscription. Users in the research department work with sensitive data. You need to prevent the research department users from accessing potentially unsafe websites by using hyperlinks embedded in email messages and documents. Users in other departments must not be restricted. What should you do?

Create a new safe links policy.

HOTSPOT -Your network contains an Active Directory domain named contoso.com that uses Microsoft System Center Configuration Manager (Current Branch).You have Windows 10 and Windows 8.1 devices. You need to ensure that you can analyze the upgrade readiness of all the Windows 8.1 devices and analyze the update compliance of all the Windows 10 devices. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Hot Area:

Create an MS Azure Log Analytics Workspace & Configure all the devices to have a commercial ID

You have a Microsoft 365 E5 tenant. You need to implement compliance solutions that meet the following requirements:✑ Use a file plan to manage retention labels. ✑ Identify, monitor, and automatically protect sensitive information. Capture employee communications for examination by designated reviewers. Which solution should you use for each requirement?

Data loss prevention - Insider Risk Management - Information Governance

Your company uses Microsoft Endpoint Configuration Manager and Microsoft Endpoint Manager to co-manage devices. Which two actions can be performed only from Endpoint Manager? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Deploy VPN Profiles to iOS devices & Publish applications to Android devices

HOTSPOT -You have a Microsoft 365 tenant that contains devices enrolled in Microsoft Intune. The devices are configured as shown in the following table.

Device 1, 2, and 3 - Device 1 Only

You have a Microsoft 365 E5 tenant that contains four devices enrolled in Microsoft Intune as shown in the following table. You plan to deploy Microsoft 365 Apps for enterprise by using Microsoft Endpoint Manager. To which devices can you deploy Microsoft 365 Apps for enterprise?

Device1 and Device3 only

You have a Microsoft 365 E5 tenant that contains the devices shown in the following table. You plan to review device startup performance issues by using Endpoint analytics. Which devices can you monitor by using Endpoint analytics?

Device1 only

You have a Microsoft 365 E5 tenant that contains the devices shown in the following table. You add custom apps to the private store in Microsoft Store Business. You plan to create a policy to show only the private store in Microsoft Store for Business. To which devices can the policy be applied?

Device2 and Device4 only

You have a hybrid Azure Active Directory (Azure AD) tenant and a Microsoft Endpoint Configuration Manager deployment. You have the devices shown in the following table. You plan to enable co-management. You need to identify which devices support co-management without requiring the installation of additional software. Which devices should you identify?

Device3 only

DRAG DROP -You have a Microsoft 365 E5 subscription. Several users have iOS devices. You plan to enroll the iOS devices in Microsoft Endpoint Manager. You need to ensure that you can create an iOS/iPadOS enrollment profile in Microsoft Endpoint Manager. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. Select and Place:

Download a certificate signing request - Create a certification from Apple Push Certificates Portal - Upload an Apple MDM push certificate to MS Endpoint Manager

You have a Microsoft 365 tenant that uses Microsoft Endpoint Manager for device management. You need to add the phone number of the help desk to the Company Portal app. What should you do?

From Customization in the Microsoft Endpoint Manager admin center, modify the support information for the tenant.

You have a Microsoft 365 tenant. You have a line-of-business application named App1 that users access by using the My Apps portal. After some recent security breaches, you implement a conditional access policy for App1 that uses Conditional Access App Control. You need to be alerted by email if impossible travel is detected for a user of App1. The solution must ensure that alerts are generated for App1 only. What should you do?

From Microsoft Cloud App Security, create a Cloud Discovery anomaly detection policy

You configure a conditional access policy. The locations settings are configured as shown in the Locations exhibit. Members of the Security reader group report that they cannot sign in to Microsoft Active Directory (Azure AD) on their devices while they are in the office. You need to ensure that the members of the Security reader group can sign in to Azure AD on their device while they are in the office. The solution must use the principle of least privilege. What should you do?

From the Azure Active Directory admin center, create a named location.

From the Microsoft Azure Active Directory (Azure AD) Identity Protection dashboard, you view the risk events shown in the exhibit. (Click the Exhibit tab.) You need to reduce the likelihood that the sign-ins are identified as risky. What should you do?

From the Conditional access blade in the Azure Active Directory admin center, create named locations.

You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com. You need to provide a user with the ability to sign up for Microsoft Store for Business for contoso.com. The solution must use the principle of least privilege. Which role should you assign to the user?

Global administrator

You have a Microsoft 365 tenant. All users are assigned the Enterprise Mobility + Security license. You need to ensure that when users join their device to Microsoft Azure Active Directory (Azure AD), the device is enrolled in Microsoft Endpoint Manager automatically. What should you configure?

MDM user scope from the Azure AD Admin Center

A user receives the following message when attempting to sign in to https://myapps.microsoft.com: Your sign-in was blocked. We've detected something unusual about this sign-in. For example, you might be signing in from a new location, device, or app. Before you can continue, we need to verify your identity. Please contact your admin.ג€Which configuration prevents the users from signing in?

Microsoft Azure Active Directory (Azure AD) Identity Protection policies

You have a Microsoft 365 E5 tenant that contains 100 Windows 10 devices. You plan to deploy a Windows 10 Security Baseline profile that will protect secrets stored in memory. What should you configure in the profile?

Microsoft Defender Credential Guard

You have Windows 10 Pro devices that are joined to an Active Directory domain. You plan to create a Microsoft 365 tenant and to upgrade the devices to Windows 10 Enterprise. You are evaluating whether to deploy Windows Hello for Business. What are two prerequisites of the deployment? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Microsoft Endpoint Manager Enrollment & Microsoft Azure AD

You have two conditional access policies named Policy1 and Policy2. Policy1 has the following settings: ✑ Assignments: - Users and groups: User1 - Cloud apps or actions: Office 365 Exchange Online - Conditions: 0 conditions selected ✑ Access controls: - Grant: Grant access - Session: 0 controls selected ✑ Enable policy: On Policy2 has the following settings: ✑ Assignments: - Users and groups: User1 - Cloud apps or actions: Office 365 Exchange Online - Conditions: 0 conditions selected ✑ Access controls:- Grant: Block access - Session: 0 controls selected ✑ Enable policy: On You need to ensure that User1 can access Microsoft Exchange Online only from devices that are marked as compliant. What should you do?

Modify the Conditions settings of Policy2.

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an on-premises Active Directory domain. The domain contains 2,000 computers that run Windows 8.1 and have applications installed as shown in the following table. You enroll all the computers in Upgrade Readiness. You need to ensure that App1 and App2 have an UpgradeDecision status of Ready to upgrade. Solution: You set the ReadyForWindows status of App2 to Highly adopted. Does this meet the goal?

No

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an on-premises Active Directory domain. The domain contains 2,000 computers that run Windows 8.1 and have applications installed as shown in the following table. You enroll all the computers in Upgrade Readiness. You need to ensure that App1 and App2 have an UpgradeDecision status of Ready to upgrade. Solution: You set the ReadyForWindows status of App1 to Highly adopted. Does this meet the goal?

No

You are deploying Microsoft Endpoint Manager. You successfully enroll Windows 10 devices in Endpoint Manager. When you try to enroll an iOS device in Endpoint Manager, you get an error. You need to ensure that you can enroll the iOS device in Endpoint Manager. Solution: You configure the Mobility (MDM and MAM) settings. Does this meet the goal?

No

You are deploying Microsoft Endpoint Manager. You successfully enroll Windows 10 devices in Endpoint Manager. When you try to enroll an iOS device in Endpoint Manager, you get an error. You need to ensure that you can enroll the iOS device in Endpoint Manager. Solution: You create the Mobility (MDM and MAM) settings. Does this meet the goal?

No

You have a computer that runs Windows 10.You need to verify which version of Windows 10 is installed. Solution: From Device Manager, you view the computer properties. Does this meet the goal?

No

You have a computer that runs Windows 10.You need to verify which version of Windows 10 is installed. Solution: From the Settings app, you select Update & Security to view the update history. Does this meet the goal?

No

Your network contains an on-premises Active Directory domain. The domain contains domain controllers that run Windows Server 2019. The functional level of the forest and the domain is Windows Server 2012 R2.The domain contains 100 computers that run Windows 10 and a member server named Server1 that runs Windows Server 2012 R2.You plan to use Server1 to manage the domain and to configure Windows 10 Group Policy settings. You install the Group Policy Management Console (GPMC) on Server1.You need to configure the Windows Update for Business Group Policy settings on Server1.Solution: You raise the domain functional level to Windows Server 2019. You copy the Group Policy Administrative Templates from a Windows 10 computer to the Netlogon share on all the domain controllers. Does this meet the goal?

No

Your network contains an on-premises Active Directory domain. The domain contains domain controllers that run Windows Server 2019. The functional level of the forest and the domain is Windows Server 2012 R2.The domain contains 100 computers that run Windows 10 and a member server named Server1 that runs Windows Server 2012 R2.You plan to use Server1 to manage the domain and to configure Windows 10 Group Policy settings. You install the Group Policy Management Console (GPMC) on Server1.You need to configure the Windows Update for Business Group Policy settings on Server1.Solution: You raise the forest functional level to Windows Server 2016. You copy the Group Policy Administrative Templates from a Windows 10 computer to the Netlogon share on all the domain controllers. Does this meet the goal?

No - Must be copied to the SYSVOL

You are deploying Microsoft Endpoint Manager. You successfully enroll Windows 10 devices in Endpoint Manager. When you try to enroll an iOS device in Endpoint Manager, you get an error. You need to ensure that you can enroll the iOS device in Endpoint Manager Solution: You create an Apple Configurator enrollment profile. Does this meet the goal?

No - need Apple Push Certificate

You are deploying Microsoft Endpoint Manager. You successfully enroll Windows 10 devices in Endpoint Manager. When you try to enroll an iOS device in Endpoint Manager, you get an error. You need to ensure that you can enroll the iOS device in Endpoint Manager. Solution: You add your user account as a device enrollment manager. Does this meet the goal?

No - need Apple Push Certification

You are deploying Microsoft Endpoint Manager. You successfully enroll Windows 10 devices in Endpoint Manager. When you try to enroll an iOS device in Endpoint Manager, you get an error. You need to ensure that you can enroll the iOS device in Endpoint Manager. Solution: You create an Apple Configurator enrollment profile. Does this meet the goal?

No - need to add to a pilot group - aka collection containing a subset of configuration manager devices.

Your network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).You manage Windows 10 devices by using Microsoft System Center Configuration Manager (Current Branch).You configure pilot co-management. You add a new device named Device1 to the domain. You install the Configuration Manager client on Device1.You need to ensure that you can manage Device1 by using Microsoft Intune and Configuration Manager. Solution: You add Device1 to an Active Directory group. Does this meet the goal?

No - need to add to a pilot group - aka collection containing a subset of configuration manager devices.

Your network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).You manage Windows 10 devices by using Microsoft System Center Configuration Manager (Current Branch).You configure pilot co-management. You add a new device named Device1 to the domain. You install the Configuration Manager client on Device1.You need to ensure that you can manage Device1 by using Microsoft Intune and Configuration Manager. Solution: You unjoin Device1 from the Active Directory domain. Does this meet the goal?

No - need to add to pilot group aka collection containing a subset of configuration manager devices.

HOTSPOT -You have a Microsoft 365 E5 tenant that contains the users shown in the following table.

No, No, Yes

You create two device compliance policies for Android devices as shown in the following table.

No, No, Yes

You have 100 computers that run Windows 8.1 and are enrolled in Upgrade Readiness. Two of the computers are configured as shown in the following table.

No, No, Yes

You have several devices enrolled in Microsoft Endpoint Manager. You have a Microsoft Azure Active Directory (Azure AD) tenant that includes the users shown in the following table.

No, No, Yes

You have three devices enrolled in Microsoft Endpoint Manager as shown in the following table.

No, No, Yes

HOTSPOT -You have a Microsoft 365 E5 tenant that contains the users shown in the following table.

No, Yes, No

HOTSPOT -You have a Microsoft 365 tenant that is signed up for Microsoft Store for Business and contains the users shown in the following table.

No, Yes, No

Your network contains an Active Directory forest named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).You use Microsoft Endpoint Configuration Manager for device management. You have the Windows 10 devices shown in the following table. (Device 1 - Collection 1---Device 2 - Collection 2) You configure Endpoint Configuration Manager co-management as follows: ✑ Automatic enrollment in Intune: Pilot✑ Pilot collection for all workloads: Collection2 You configure co-management workloads as shown in the following exhibit.

No, Yes, Yes

HOTSPOT -You have a Microsoft 365 E5 subscription that uses Microsoft Intune. You have devices enrolled in Intune as shown in the following table.

Profile 1 & 4 Only - Profile 3 Only

Your network contains an Active Directory domain named contoso.com. All client devices run Windows 10 and are joined to the domain. You update the Windows 10 devices by using Windows Update for Business. What is the maximum amount of time you can defer Windows 10 updates? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Quality = 30; Feature = 365

Your network contains an on-premises Active Directory domain that syncs to Azure Active Directory (Azure AD).The domain contains two servers named Server1 and Server2 that run Windows Server 2016. Server1 has the File Server Resource Manager role service installed. You need to configure Server1 to use the Azure Rights Management (Azure RMS) connector. You install the Microsoft Management connector on Server1.What should you do next on Server1?

Run the GenConnectorConfig.ps1 script. (Not applicable to new exam)

You have computers that run Windows 10 Enterprise and are joined to the domain. You plan to delay the installation of new Windows builds so that the IT department can test application compatibility. You need to prevent Windows from being updated for the next 30 days. Which two Group Policy settings should you configure? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Select when Preview Builds and Feature Updates are received & Manage preview builds

Your company has a Microsoft 365 E3 subscription. All devices run Windows 10 Pro and are joined to Microsoft Azure Active Directory (Azure AD).You need to change the edition of Windows 10 to Enterprise the next time users sign in to their computer. The solution must minimize downtime for the users. What should you use?

Subscription Activation

HOTSPOT -You have a Microsoft 365 E5 tenant that contains the users shown in the following table.

User 2 & 3 - User 1, 2, 3, 4

Your company has a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com. You sign up for Microsoft Store for Business. The tenant contains the users shown in the following table. Microsoft Store for Business has the following Shopping behavior settings: ✑ Make everyone a Basic Purchaser is set to Off. ✑ Allow app requests is set to On. You need to identify which users can add apps to the Microsoft Store for Business private store. Which users should you identify?

User1 only

Your company has a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com and a Microsoft 365 subscription. The company recently hired four new users who have the devices shown in the following table. You configure the Microsoft 365 subscription to ensure that the new devices enroll in Microsoft Endpoint Manager automatically Which users have a device that can enroll in Microsoft Endpoint Manager automatically?

User2 only

You have a Microsoft 365 E5 subscription. You plan to deploy 100 new Windows 10 devices. You need to identify the appropriate version of Windows 10 for the new devices. The version must meet the following requirements: ✑ Be serviced for a minimum of 24 months. Support Microsoft Application Virtualization (App-V). Which version should you identify?

Windows 10 Enterprise, version 1909

You use Microsoft System Center Configuration Manager (Current Branch) to manage devices. Your company uses the following types of devices :✑ Windows 10 ✑ Windows 8.1 ✑ Android ✑ iOS Which devices can be managed by using co-management?

Windows 10 only

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an on-premises Active Directory domain. The domain contains 2,000 computers that run Windows 8.1 and have applications installed as shown in the following table. You enroll all the computers in Upgrade Readiness. You need to ensure that App1 and App2 have an UpgradeDecision status of Ready to upgrade. Solution: You set the importance status of App2 to Low install count. Does this meet the goal?

Yes

You are deploying Microsoft Endpoint Manager. You successfully enroll Windows 10 devices in Endpoint Manager. When you try to enroll an iOS device in Endpoint Manager, you get an error. You need to ensure that you can enroll the iOS device in Endpoint Manager. Solution: You configure the Apple MDM Push certificate. Does this meet the goal?

Yes

You have a computer that runs Windows 10.You need to verify which version of Windows 10 is installed. Solution: At a command prompt, you run the winver.exe command. Does this meet the goal?

Yes

You have a computer that runs Windows 10.You need to verify which version of Windows 10 is installed. Solution: From the Settings app, you select System, and then you select About to view information about the system. Does this meet the goal?

Yes

Your network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).You manage Windows 10 devices by using Microsoft System Center Configuration Manager (Current Branch).You configure pilot co-management. You add a new device named Device1 to the domain. You install the Configuration Manager client on Device1.You need to ensure that you can manage Device1 by using Microsoft Intune and Configuration Manager. Solution: Define a Configuration Manager device collection as the pilot collection. Add Device1 to the collection. Does this meet the goal?

Yes

Your network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).You manage Windows 10 devices by using Microsoft System Center Configuration Manager (Current Branch).You configure pilot co-management. You add a new device named Device1 to the domain. You install the Configuration Manager client on Device1.You need to ensure that you can manage Device1 by using Microsoft Intune and Configuration Manager. Solution: You add Device1 to a Configuration Manager device collection. Does this meet the goal?

Yes

Your network contains an on-premises Active Directory domain. The domain contains domain controllers that run Windows Server 2019. The functional level of the forest and the domain is Windows Server 2012 R2.The domain contains 100 computers that run Windows 10 and a member server named Server1 that runs Windows Server 2012 R2.You plan to use Server1 to manage the domain and to configure Windows 10 Group Policy settings. You install the Group Policy Management Console (GPMC) on Server1.You need to configure the Windows Update for Business Group Policy settings on Server1.Solution: You copy the Group Policy Administrative Templates from a Windows 10 computer to Server1.Does this meet the goal?

Yes

Your network contains an on-premises Active Directory domain. The domain contains domain controllers that run Windows Server 2019. The functional level of the forest and the domain is Windows Server 2012 R2.The domain contains 100 computers that run Windows 10 and a member server named Server1 that runs Windows Server 2012 R2.You plan to use Server1 to manage the domain and to configure Windows 10 Group Policy settings. You install the Group Policy Management Console (GPMC) on Server1.You need to configure the Windows Update for Business Group Policy settings on Server1.Solution: You upgrade Server1 to Windows Server 2019.Does this meet the goal?

Yes

HOTSPOT -You have three devices enrolled in Microsoft Intune as shown in the following table.

Yes, No

HOTSPOT -You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table.

Yes, No, NO

HOTSPOT -You have a Microsoft 365 E5 tenant that contains two users named User1 and User2 and the groups shown in the following table.

Yes, No, No

HOTSPOT -You have a Microsoft 365 subscription that contains the users shown in the following table.

Yes, No, No

You have several devices enrolled in Microsoft Endpoint Manager. You have a Microsoft Azure Active Directory (Azure AD) tenant that includes the users shown in the following table.

Yes, No, No

HOTSPOT -You have a Microsoft 365 subscription that contains the users in the following table.

Yes, No, Yes

You have the Microsoft Azure Active Directory (Azure AD) users shown in the following table. You create a conditional access policy that has the following settings:✑ The Assignments settings are configured as follows:1. Users and groups: Group12. Cloud apps: Microsoft Office 365 Exchange Online3. Conditions: Include All device state, exclude Device marked as compliant✑ Access controls is set to Block access. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Hot Area:

Yes, No, Yes

You have three devices enrolled in Microsoft Endpoint Manager as shown in the following table

Yes, Yes, No

You have a Microsoft 365 E5 subscription that uses an Azure Active Directory (Azure AD) tenant named contoso.com. You need to ensure that users can enroll devices in Microsoft Endpoint Manager without manually entering the address of Microsoft Endpoint Manager. Which two DNS records should you create? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

a CNAME record for EnterpriseEnrollment.contoso.com & a CNAME record for EnterpriseRegistration.contoso.com

Your company has 10 offices. The network contains an Active Directory domain named contoso.com. The domain contains 500 client computers. Each office is configured as a separate subnet. You discover that one of the offices has the following:✑ Computers that have several preinstalled applications✑ Computers that use nonstandard computer names✑ Computers that have Windows 10 preinstalled✑ Computers that are in a workgroup You must configure all computers in the office to meet the following corporate requirements: All computers in the office must be joined to the domain. ✑ All computers in the office must have computer names that use a prefix of CONTOSO. ✑ All computers in the office must only have approved corporate applications installed. You need to recommend a solution to redeploy the computers. The solution must minimize the deployment time. Which deployment method should you recommend?

a provisioning package

You have a Microsoft 365 E5 tenant that uses Microsoft Intune. You need to ensure that users can select a department when they enroll their device in Intune. What should you create?

device categories

Your company has multiple offices. You have a Microsoft 365 E5 tenant that uses Microsoft Intune for device management. Each office has a local administrator. You need to ensure that the local administrators can manage only the devices in their respective office. What should you use?

scope tags

Your company has offices in five cities. The company has a Microsoft 365 tenant. Each office is managed by a local administrator. You plan to deploy Microsoft Intune. You need to recommend a solution to manage resources in Intune that meets the following requirements:✑ Local administrators must be able to manage only the resources in their respective office.✑ Local administrators must be prevented from managing resources in other offices.✑ Administrative effort must be minimized. What should you include in the recommendation?

scope tags

You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.onmicrosoft.com. You have a Microsoft 365 subscription. You need to ensure that administrators can manage the configuration settings for all the Windows 10 devices in your organization. What should you configure?

the mobile device management (MDM) authority

Your network contains an Active Directory domain named contoso.com. The domain contains 100 Windows 8.1 devices. You plan to deploy a custom Windows 10 Enterprise image to the Windows 8.1 devices. You need to recommend a Windows 10 deployment method. What should you recommend?

wipe and load refresh


Related study sets

NUR 635 Advanced Pharmacology Final

View Set

02 - الآمــرون بالصــــرف (Les Ordonnateurs)

View Set

Image Acq. Unit 4 Quality Factors Radiographic Distortion

View Set

ΒΙΟΛΟΓΙΑ -1ο Κεφάλαιο β( Κύτταρο : η μονάδα της ζωής)

View Set

AWS Certified Cloud Practitioner

View Set

Chapter 39- Vehicle Extrication and Special Rescue Q & A

View Set

Chapter 25 face and neck injuries

View Set