Your network is configured as an Active Directory Domain Services (AD DS) domain. You also have an Azure Active Directory (Azure AD) domain. All domain clients are hybrid Azure AD-joined. The company recently upgraded most of its on-premises clients to Windows 10 with an Enterprise E5 Microsoft 365 license. All client computers run the System Center Configuration Manager (SCCM) client. You plan to use SCCM to deploy configuration files to domain clients. Your company subscribes to the Microsoft Defender Advanced Threat Protection (ATP) online service. You want to configure onboarding to support ATP for domain-joined clients. You need to create an onboarding configuration file. What should you use to create the file?
- D. Azure portal
Your company has a Microsoft 365 subscription that includes Enterprise Mobility plus Security. Members of a group named Marketing use devices that run iOS. You need to ensure that members of the marketing department can install Microsoft OneDrive from the Company Portal. What should you do?
You have a device named Devicel. Devicel is running Windows 10 Enterprise. You register Devicel with Azure Active Directory (Azure AD). You need to confirm that the device is Azure AD joined. What command-line tool should you use?
CompayA has 400 mobile devices running a mixture of iOS and Android. You plan to implement Microsoft Intune for Mobile Device Management (MDM). All devices must be enrolled in Microsoft Intune. You need to block devices that are running a version of iOS older than 12.0. Which should you use?
CompanyA has 25,000 devices running Windows 10. All Windows 10 devices are managed with System Center Configuration Manager (SCCM) and co-managed with Microsoft Intune. The following workloads have been moved to Microsoft Intune: * Compliance policies * Windows Update policies All Windows 10 devices are hybrid Azure Active Directory (Azure AD) joined All Windows 10 devices have been configured for Upgrade Readiness. You are planning to create a report that contains information about device enrollment and compliance. The report needs to contain the following information: * Device Name * Managed By * Compliance * Enrollment Date * Last Check-in Your solution should minimize administrative effort. Which tool should you use?
Your network has Windows 10 network computers configured as hybrid joined to Active Directory Domain Services (AD DS) and an Azure Active Directory (Azure AD) domain. All domain computers are part of the same System Center Operations Manager management group. You have an Azure Log Analytics workspace named DefWorkspace. You specified this workspace when you installed Microsoft Monitoring Agent on the domain computers. The Operations Manager management group is also configured to send data to this workspace. You create a second Log Analytics workspace named SpecWorkspace. You want to have performance and event log data written to the workspace. You need to ensure that domain computers send data to SpecWorkspace and continue to send data to DefWorkspace. What should you use to configure this?
CompanyA has 2,500 devices running Windows 10. These devices are joined to Windows Active Directory and hybrid joined to Azure Active Directory (Azure AD). You enable Enterprise State Roaming (ESR) for all employees. You have an organizational unit (OU) named OU1. OU1 contains all devices running Windows 10. You have a Group Policy object (GPO) named Policyl. Policyl is linked to OU1. You need to configure Policyl to meet the following requirements: * Prevent ESR from syncing wireless profiles. * Minimize interference with other ESR sync groups. Which setting should you configure?
- B. Do not sync
Your company supports on-premises Azure Active Directory (Azure AD) hybrid-joined devices. All devices are enrolled in Intune. Your company has offices in the UK, Australia, and Singapore. Each office contains several hundred users. The company migrates the mailboxes of all users to Exchange Online. You need to ensure that users can access Exchange Online mailboxes from devices in office locations only. What should you do?
Your company has Microsoft 365 and Azure subscriptions. All company Windows 10 devices are managed by Microsoft Intune. You plan to monitor the device health of the Windows 10 devices by using Windows Analytics. You need to configure all Windows 10 devices to send telemetry data to Windows Analytics. What should you do?
- A. Create a Log Analytics workspace. Add a solution to the workspace. Deploy the Commercial ID key to the devices.
- C. Install the Azure Log Analytics Agent on the devices. Configure the agent with an Azure subscription ID.
Your network is configured as an Active Directory Domain Services (AD DS) domain. You use System Center Configuration Manager (SCCM) to manage Windows 10 domain member devices. Your company has an Azure subscription, and all domain users have Microsoft work accounts. The company plans to use Windows Analytics Device Health to monitor Windows 10 clients. You add the Device Health solution to your Azure subscription. You need to enroll the devices in Windows Analytics. What should you do first?
Your company collects data into a Log Analytics workbook from various sources, including: * Azure resources * Operations Manager * Configuration Manager You have an Automation account linked to the Log Analytics workspace. The Automation account is used with an existing runbook that performs periodic management tasks. Your company plans to use a monitoring solution to collect and analyze data for a business-critical application. You are not currently running any monitoring solution. You need to add a monitoring solution from outside Azure Marketplace. Data should be maintained in the same location as data already being collected in the workbook. What should you do first?
You help manage Windows Active Directory (AD DS) and Azure Active Directory (Azure AD) for CompanyA. CompanyA has 2,500 devices joined to AD DS and running the following operating systems: * Windows 10 Enterprise * Windows 8.1 Enterprise You are planning to enable hybrid Azure AD join using Azure AD Connect. During the configuration of hybrid Azure AD join, you are unable to enable support for Windows down-level domain-joined devices, as shown in the exhibit.
Your company wants to implement compliance policies and conditional access for network devices that include: * Windows 10 * Android * iOS * macOS You create and assign compliance policies for network devices. The devices are enrolled with Intune. Devices that are not compliant are automatically given a status of Not compliant. You need to ensure that an email is sent to the device user when a device is identified as out of compliance. What should you do first?
ComanyA has 300 corporate-owned devices running Android Enterprise. These devices are enrolled in Microsoft Intune. These devices require the following configuration: * Fingerprint unlock * Always-on VPN You need to create a device configuration profile that meets these requirements. Which two categories should you configure? Each correct answer presents part of the solution
CompanyA has 10,000 devices running Windows 10. You plan to implement Microsoft Intune for Mobile Device Management (MDM). You need to configure Microsoft Intune to support automatic device enrollment for all Windows 10 devices. Which two actions should you perform? Each correct answer presents part of the solution.
CompanyA has 3.000 devices running Windows 10. These devices are hybrid Azure Active Directory (Azure AD) joined and enrolled in Microsoft lntune. You have a named location in Azure AD named HQ. HQ has an IP range of 10.239.12.0/21. You plan to enforce Multi-Factor Authentication (MFA) for devices that access Office 365 Exchange Online from a network other than HQ. You need to configure the correct policy. What tool should you use?
Your network is configured as an Active Directory Domain Services (AD DS) domain. Windows 10 client devices are hybrid-joined with Azure Active Directory (Azure AD). All Windows 10 devices are enrolled in Intune. You company wants to collect data from cloud-based and on-premises sources. The monitoring solution must include support for: * Application availability, performance, and use * Infrastructure performance * Network data flows You need to implement the appropriate solution. What should you use?
All company devices are joined to Azure Active Directory (Azure AD), and all users have Azure AD accounts. Your company plans to use Microsoft Store for Business. You need to enable an Azure AD user named Admin1 to sign up for Microsoft Store for Business. Your solution should follow the principle of least privilege. Which Azure AD role should you assign to Admin1?
19. CompanyA has 2,500 devices running Windows 10, version 1709. These devices are managed with System Center Configuration Manager (SCCM) and co-managed with Microsoft Intune. You have a requirement to upgrade these devices to Windows 10, version 1809 using the in-place upgrade method. You are planning to use Upgrade Readiness to prepare for the in-place upgrade. You need to enable Upgrade Readiness for these devices. What should you do first?
You manage Android, iOS, and Windows devices with Microsoft Intune. You have a device named Device1. Devicel1 is joined to Azure Active Directory (Azure AD) and is configured as shown in the exhibit. You have a security group named Group1. Device1 is a member of Group1. You have a Windows Information Protection (WIP) policy named Policy1. Policy1 is configured to block unsafe sharing for the Microsoft OneDrive desktop app. You assign Policy1 to User1. You need to configure WIP to apply to Device1 when User1 signs in. Which action should you take first?
All corporate laptops to run Windows 10 v1793 or v1809. You migrate Group Policy objects (GPOs) to mobile device management (MDM) policies. You make changes to some of the MDM policies including setting the MDMWinsOverGP to a value of 1 You receive reports from some users that MDM policies are not being applied. You need to resolve the issue so that MDM policies are applied. What should you do?
22. You deploy multiple applications via a provisioning package using the default options. After you apply the package to a system, you find that one of the applications is missing. You install the application manually, and it installs without error. You want to monitor activity when applying future provisioning packages with granular reporting and custom error and status messages. You need to determine how accomplish this. What should you do?
CompanyA has 2,500 devices running Windows 10. These devices are joined to Windows Active Directory and hybrid joined to Azure Active Directory (Azure AD). You have an organizational unit (OU) named OU1. OU1 contains all devices running Windows 10. You have a Group Policy object (GPO) named Policyl. Policyl has the following setting configured: * Enable OneDrive Files On-Demand Policyl is linked to OU1. You plan to deploy Known Folder Redirection for OneDrive. Some users have Known Folder Redirection enabled and set to a personal OneDrive account. You need to configure Policyl to redirect all known folders to CompanyAs OneDrive tenant. What setting should you configure?
You are the mobile device administrator for SchoolA. SchoolA uses Microsoft lntune to manage their mobile devices. You plan to configure device enrollment for devices running iOS. You need to complete the prerequisites for iOS enrollment. What should you do?
Your company has the following laptops: * Windows 10 version 1703: 500 units * Windows 10 version 1803: 700 units * Windows 10 version 1809: 1000 units Laptops running v1703 and v1803 are joined to your on-premises Active Directory Domain Services (AD DS) domain. Laptops running v1809 are Azure Active Directory (Azure AD) hybrid joined only. Laptops running Windows 10 v1703 and v1803 are managed using System Center Configuration Manager (SCCM). Laptops running Windows 10 v1809 are managed using Intune. You need to prepare your environment to apply the same conditional settings to all devices, including multi-factor authentication (MFA). In addition, you need to be able to migrate all workloads to the cloud in the coming year. The solution must minimize administrative effort. What three actions should you recommend? Each correct answer presents part of the solution
About Individual Course:
|Learning Style||Self-Paced Learning|
|Course Duration||1 Hour|