Microsoft 365 Administrator Expert MS-102 Practice Question

You manage 25 000 Windows 11 computers that are hybrid Azure AD joined and managed through Microsoft Intune. The devices run Windows 11 22H2 Enterprise (OS build 22621.2134) and are currently not onboarded to Microsoft Defender for Endpoint (MDE).

You must ensure that all existing and future Intune-managed Windows 11 devices are automatically onboarded to MDE without requiring users to run scripts or download onboarding packages. The solution must minimise administrative effort and support centralised off-boarding when devices are retired.

Which Intune configuration profile should you deploy?

  • Device configuration - Custom profile that runs WindowsOnboardingScript.cmd as a PowerShell script

  • Endpoint security - Endpoint detection and response (EDR) profile that sets Microsoft Defender for Endpoint to Enable

  • Endpoint security - Antivirus profile that sets Real-time protection to On

  • Settings catalog profile that deploys the onboarding package through the OMA-URI OnboardingBlob setting

Microsoft 365 Administrator Expert MS-102
Manage security and threats by using Microsoft Defender XDR
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot