Microsoft MD-102 Compliance Conditional Access Windows Hello LAPS And Local Groups Practice Test
Skills 1.3 • 30 original questions
This Microsoft MD-102 Endpoint Administrator practice test focuses on compliance conditional access windows hello laps and local groups through original scenario-based questions aligned to the skills measured as of July 24, 2026. Use the full ExamSnap MD-102 collection for broader practice across all current skill areas. For broader exam preparation, review the Microsoft MD-102 Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
During a tenant consolidation at Tailspin Toys, the service desk lead must evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements. Which action most directly satisfies the requirement? The affected devices are in the field-device cohort, rollout wave 1.
Correct answer: B
Why: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
Option review:
A: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
B: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
D: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
Learning point: Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
Alpine Ski House is revising endpoint operations for a branch migration. Administrators need to block access to protected resources unless the device meets Intune compliance requirements. Which implementation should the desktop engineer select for the developer cohort, rollout wave 1?
Correct answer: E
Why: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.
Option review:
A: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
B: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
D: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.
Learning point: Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
A ticket escalated to the security administrator at Wide World Importers states one non-negotiable goal: deploy Windows Hello for Business authentication settings to managed Windows endpoints. Which choice is the strongest fit for the frontline-user cohort, rollout wave 1?
Correct answer: D
Why: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
Option review:
A: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
B: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
D: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
E: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
Learning point: Configure Windows Hello for Business through Intune policy
For the kiosk cohort, rollout wave 1 at Northwind Traders, a operations review can proceed only if the team can centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices. What should the endpoint administrator configure?
Correct answer: A
Why: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
Option review:
A: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
B: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
C: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
D: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
E: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
Learning point: Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
The endpoint architecture review at Tailspin Toys focuses on this requirement: centrally control which accounts are members of local Windows groups such as Administrators. Which Microsoft management action is most appropriate for the new-hire cohort, rollout wave 1?
Correct answer: A
Why: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: centrally control which accounts are members of local Windows groups such as Administrators.
Option review:
A: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: centrally control which accounts are members of local Windows groups such as Administrators.
B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.
C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.
D: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.
E: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.
Learning point: Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
A change advisory board at Alpine Ski House asks how to evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements during a remote-work deployment. Which proposed action should the endpoint administrator approve for the contractor cohort, rollout wave 2?
Correct answer: A
Why: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
Option review:
A: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
B: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
D: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
Learning point: Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
Wide World Importers has already ruled out manual per-device administration. For the lab-device cohort, rollout wave 2, the remaining requirement is to block access to protected resources unless the device meets Intune compliance requirements. Which choice best addresses it?
Correct answer: D
Why: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.
Option review:
A: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
C: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
D: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.
E: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
Learning point: Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
During post-pilot review at Northwind Traders, the desktop engineer identifies a gap: the organization still needs to deploy Windows Hello for Business authentication settings to managed Windows endpoints. Which action should be added before the pilot ring, rollout wave 2 moves to production?
Correct answer: D
Why: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
Option review:
A: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
B: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
C: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
D: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
E: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
Learning point: Configure Windows Hello for Business through Intune policy
The security administrator at Tailspin Toys is comparing several cloud-management options for a tenant consolidation. Which one directly enables the team to centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices for the production ring, rollout wave 2?
Correct answer: D
Why: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
Option review:
A: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
B: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
D: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
E: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
Learning point: Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
A security and operations workshop at Alpine Ski House defines the desired outcome as follows: centrally control which accounts are members of local Windows groups such as Administrators. Which implementation should be chosen for the executive-device cohort, rollout wave 2?
Correct answer: C
Why: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: centrally control which accounts are members of local Windows groups such as Administrators.
Option review:
A: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.
B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.
C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: centrally control which accounts are members of local Windows groups such as Administrators.
D: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.
E: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.
Learning point: Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
Which action best matches this technical purpose for the remote-user cohort, rollout wave 3: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met.
Correct answer: C
Why: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met..
Option review:
A: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met..
B: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met..
C: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met..
D: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met..
E: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met..
Learning point: Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
An administrator at Northwind Traders describes the needed capability this way: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. Which option should be associated with that requirement for the shared-device cohort, rollout wave 3?
Correct answer: E
Why: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy..
Option review:
A: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy..
B: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy..
C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy..
D: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy..
E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy..
Learning point: Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
During a design validation for the field-device cohort, rollout wave 3, Tailspin Toys documents the following behavior: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. Which endpoint-management feature or action is being described?
Correct answer: C
Why: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device..
Option review:
A: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device..
B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device..
C: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device..
D: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device..
E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device..
Learning point: Configure Windows Hello for Business through Intune policy
The desktop engineer must identify the Microsoft endpoint-management capability that provides this function for the developer cohort, rollout wave 3: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. Which choice is correct?
Correct answer: B
Why: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation..
Option review:
A: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation..
B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation..
C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation..
D: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation..
E: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation..
Learning point: Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
A runbook for the frontline-user cohort, rollout wave 3 contains this description: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. Which implementation belongs in that runbook?
Correct answer: B
Why: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..
Option review:
A: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..
B: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..
C: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..
D: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..
E: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..
Learning point: Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
Northwind Traders is troubleshooting a branch migration. Evidence shows that the decisive requirement is to evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements. Which action should the Intune administrator investigate first for the kiosk cohort, rollout wave 4?
Correct answer: E
Why: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
Option review:
A: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
B: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
D: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
E: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
Learning point: Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
After eliminating network and licensing causes, the Microsoft 365 administrator at Tailspin Toys determines that success depends on the ability to block access to protected resources unless the device meets Intune compliance requirements. Which endpoint-management action should be checked next for the new-hire cohort, rollout wave 4?
Correct answer: E
Why: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.
Option review:
A: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
B: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
C: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
D: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.
Learning point: Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
A service-desk escalation during a operations review has been narrowed to one management requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints. Which configuration is the most relevant starting point for the contractor cohort, rollout wave 4?
Correct answer: E
Why: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
Option review:
A: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
D: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
E: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
Learning point: Configure Windows Hello for Business through Intune policy
The failure pattern at Wide World Importers affects the lab-device cohort, rollout wave 4. Before making unrelated policy changes, the service desk lead needs a solution that will centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices. Which action is most directly relevant?
Correct answer: B
Why: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
Option review:
A: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
D: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
E: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
Learning point: Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
While investigating a Windows 11 rollout, Northwind Traders confirms the environment must centrally control which accounts are members of local Windows groups such as Administrators. Which Microsoft endpoint-management capability should be validated for the pilot ring, rollout wave 4?
Correct answer: A
Why: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: centrally control which accounts are members of local Windows groups such as Administrators.
Option review:
A: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: centrally control which accounts are members of local Windows groups such as Administrators.
B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.
C: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.
D: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.
E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.
Learning point: Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
Two teams at Tailspin Toys propose different approaches for the production ring, rollout wave 5. The selection criterion is simple: the chosen approach must evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements. Which option should win the technical comparison?
Correct answer: B
Why: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
Option review:
A: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
B: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
C: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
D: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
E: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
Learning point: Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
For the executive-device cohort, rollout wave 5, Alpine Ski House wants the least indirect solution to this goal: block access to protected resources unless the device meets Intune compliance requirements. Which action aligns most closely with that requirement?
Correct answer: B
Why: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.
Option review:
A: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
B: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.
C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
D: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
E: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
Learning point: Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
A modernization plan at Wide World Importers includes a tenant consolidation. The Microsoft 365 administrator is asked to choose the control that specifically helps the organization deploy Windows Hello for Business authentication settings to managed Windows endpoints. Which choice fits best for the remote-user cohort, rollout wave 5?
Correct answer: C
Why: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
Option review:
A: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
B: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
C: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
D: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
E: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
Learning point: Configure Windows Hello for Business through Intune policy
The shared-device cohort, rollout wave 5 is moving into a controlled rollout at Northwind Traders. Which action should be included when the stated management objective is to centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices?
Correct answer: B
Why: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
Option review:
A: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
D: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
E: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
Learning point: Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
Tailspin Toys is replacing an ad hoc process during a application modernization. The replacement must reliably centrally control which accounts are members of local Windows groups such as Administrators. Which endpoint-management approach should the service desk lead implement for the field-device cohort, rollout wave 5?
Correct answer: A
Why: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: centrally control which accounts are members of local Windows groups such as Administrators.
Option review:
A: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: centrally control which accounts are members of local Windows groups such as Administrators.
B: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.
C: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.
D: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.
E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.
Learning point: Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
An audit finding for the developer cohort, rollout wave 6 says the current process does not consistently evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements. Which Microsoft endpoint-management action most directly closes that gap?
Correct answer: A
Why: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
Option review:
A: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
D: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
E: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.
Learning point: Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
The security administrator at Wide World Importers needs a repeatable configuration for the frontline-user cohort, rollout wave 6. It must block access to protected resources unless the device meets Intune compliance requirements. Which choice should be implemented instead of relying on manual endpoint work?
Correct answer: A
Why: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.
Option review:
A: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.
B: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
D: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
E: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.
Learning point: Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
During readiness testing at Northwind Traders, the kiosk cohort, rollout wave 6 fails a business requirement because administrators cannot yet deploy Windows Hello for Business authentication settings to managed Windows endpoints. Which action should be implemented before rollout continues?
Correct answer: E
Why: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
Option review:
A: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
B: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
D: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
E: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.
Learning point: Configure Windows Hello for Business through Intune policy
A governance review asks the Microsoft 365 administrator to justify the control selected for the new-hire cohort, rollout wave 6. The requirement is to centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices. Which action has the clearest technical alignment?
Correct answer: B
Why: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
Option review:
A: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
D: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
E: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.
Learning point: Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
For a security hardening project, Alpine Ski House needs an endpoint-management capability with this effect: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. Which option most accurately provides that capability for the contractor cohort, rollout wave 6?
Correct answer: C
Why: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..
Option review:
A: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..
B: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..
C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..
D: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..
E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..
Learning point: Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
Popular posts
Recent Posts
