Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
You have a Microsoft 365 E5 subscription.
You need to create a dynamic device group that will contain any device that has the word Marketing in its name. Which device membership rule should you use?
To create a dynamic device group with devices containing 'Marketing' in their name, you should use the device membership rule: (device.displayName -contains 'Marketing'). This rule uses the -contains operator to match any device where the displayName attribute contains the word 'Marketing'. Alternative syntax that works includes (device.displayName -match '.*Marketing.*') using regex pattern matching. The rule must target the displayName attribute and use case-insensitive matching.
You use Microsoft Defender for Endpoint to protect computers that run Windows 10.
You need to assess the differences between the configuration of Microsoft Defender for Endpoint and the Microsoft-recommended configuration baseline.
Which tool should you use?
To assess the differences between your current Microsoft Defender for Endpoint configuration and the Microsoft-recommended configuration baseline, you should use the Defender for Endpoint Configuration Manager (also known as the Configuration Assessment tool or Defender for Endpoint baseline comparison tool).
This tool allows you to compare your existing Defender for Endpoint settings against Microsoft's recommended security baselines. It provides a detailed analysis of configuration gaps and helps identify areas where your configuration deviates from best practices and security recommendations for protecting Windows 10 computers.
Your company has an Azure AD tenant named contoso.com that contains several Windows 10 devices.
When you join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin.
You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com.
Solution: From the Microsoft Entra admin center, you configure automatic mobile device management (MDM) enrollment. From the Microsoft Intune admin center, you configure the Windows Hello for Business enrollment options.
Does this meet the goal?
You have following types of devices enrolled in Microsoft Intune:
* Windows 10
* Android
* iOS
For which types of devices can you create VPN profiles in Microsoft Intune admin center?
In Microsoft Intune admin center, VPN profiles can be created for: Windows 10, Android, and iOS devices. Intune supports creating and deploying VPN profiles to all three device types listed. Each platform supports different VPN connection types (IKEv2, L2TP, PPTP, etc.), but all three device types can have VPN profiles assigned to them. The answer depends on whether the question is asking which device types CAN have VPN profiles (answer: all three - Windows 10, Android, iOS), or if it's asking about specific VPN protocols supported by each type. Assuming the question asks which types support VPN profiles in general, the answer is all three: Windows 10, Android, and iOS.
You have a Hyper-V host that contains the virtual machines shown in the following table.

On which virtual machines can you install Windows 11?
This question references a table of virtual machines that is not provided in the question text. To properly answer which virtual machines can run Windows 11, you would need to review the specifications shown in that table, including processor architecture (Generation 2 VMs are required), RAM, storage, and other hardware requirements. Windows 11 requires specific hardware features such as TPM 2.0, UEFI firmware, Secure Boot capability, and a compatible processor (typically 8th generation Intel or 2nd generation AMD Ryzen or newer). The answer would depend on the specific configuration of each virtual machine listed in the table.
417 questions covering all exam domains, starting from $20
Exam domains verified against: Official Microsoft MD-102 exam guide, last checked September 2026.
This domain covers adding devices to Microsoft Entra ID and enrolling them to Microsoft Intune. You need to understand device registration, enrollment methods, and initial configuration for hybrid and cloud-native management scenarios. Hands-on experience with Windows Autopilot and enrollment policies is essential.
This is the largest domain and focuses on deploying and upgrading Windows clients via cloud-based tools, designing device configuration profiles, and implementing Intune Suite capabilities. You will also need to perform remote actions on managed devices such as troubleshooting and retirement. Proficiency with Intune configuration at depth is critical here.
This domain requires you to deploy and update applications across managed endpoints and implement app protection and app configuration policies. You need to understand application packaging, distribution methods through Intune, and how to enforce security and compliance policies for apps.
This domain covers configuring endpoint security including antivirus, encryption, and firewall settings via Intune policies. You also need to manage device updates and understand compliance monitoring. Knowledge of Microsoft Defender for Endpoint integration and security baselines is important.
Sample question from this domain above: Q4
Common questions about the exam itself