Microsoft 365 Endpoint Administrator Associate MD-102 Practice Question

Your company manages Microsoft Entra ID-joined Windows 11 laptops with Microsoft Intune. You need to grant local administrator rights to the Azure AD group named SecOps on every device while keeping all existing built-in members of the Administrators group. You must accomplish this by using an Intune policy rather than scripts. Which Intune policy type should you deploy?

  • An Endpoint security account protection policy that uses Local user group membership settings

  • A compliance policy that requires the SecOps group to be present in the local Administrators group

  • A PowerShell script deployed by Intune that runs the Add-LocalGroupMember cmdlet

  • A device configuration profile created from the Settings catalog that applies the Restricted Groups policy

Microsoft 365 Endpoint Administrator Associate MD-102
Prepare infrastructure for devices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot