Microsoft MD-102 Compliance Conditional Access Windows Hello LAPS And Local Groups Practice Test

 

Skills 1.3 • 30 original questions

This Microsoft MD-102 Endpoint Administrator practice test focuses on compliance conditional access windows hello laps and local groups through original scenario-based questions aligned to the skills measured as of July 24, 2026. Use the full ExamSnap MD-102 collection for broader practice across all current skill areas. For broader exam preparation, review the Microsoft MD-102 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

During a tenant consolidation at Tailspin Toys, the service desk lead must evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements. Which action most directly satisfies the requirement? The affected devices are in the field-device cohort, rollout wave 1.

  1. Configure Windows Hello for Business through Intune policy
  2. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  3. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  4. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  5. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant

Correct answer: B

Why: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

Option review:

A: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

B: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

D: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

Learning point: Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices

Question 2

Alpine Ski House is revising endpoint operations for a branch migration. Administrators need to block access to protected resources unless the device meets Intune compliance requirements. Which implementation should the desktop engineer select for the developer cohort, rollout wave 1?

  1. Configure Windows Hello for Business through Intune policy
  2. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  3. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  4. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  5. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant

Correct answer: E

Why: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.

Option review:

A: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

B: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

D: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.

Learning point: Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant

Question 3

A ticket escalated to the security administrator at Wide World Importers states one non-negotiable goal: deploy Windows Hello for Business authentication settings to managed Windows endpoints. Which choice is the strongest fit for the frontline-user cohort, rollout wave 1?

  1. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  2. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  3. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  4. Configure Windows Hello for Business through Intune policy
  5. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed

Correct answer: D

Why: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

Option review:

A: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

B: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

D: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

E: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

Learning point: Configure Windows Hello for Business through Intune policy

Question 4

For the kiosk cohort, rollout wave 1 at Northwind Traders, a operations review can proceed only if the team can centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices. What should the endpoint administrator configure?

  1. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  2. Configure Windows Hello for Business through Intune policy
  3. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  4. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  5. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices

Correct answer: A

Why: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

Option review:

A: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

B: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

C: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

D: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

E: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

Learning point: Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed

Question 5

The endpoint architecture review at Tailspin Toys focuses on this requirement: centrally control which accounts are members of local Windows groups such as Administrators. Which Microsoft management action is most appropriate for the new-hire cohort, rollout wave 1?

  1. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  2. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  3. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  4. Configure Windows Hello for Business through Intune policy
  5. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices

Correct answer: A

Why: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: centrally control which accounts are members of local Windows groups such as Administrators.

Option review:

A: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: centrally control which accounts are members of local Windows groups such as Administrators.

B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.

C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.

D: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.

E: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.

Learning point: Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices

Question 6

A change advisory board at Alpine Ski House asks how to evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements during a remote-work deployment. Which proposed action should the endpoint administrator approve for the contractor cohort, rollout wave 2?

  1. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  2. Configure Windows Hello for Business through Intune policy
  3. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  4. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  5. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant

Correct answer: A

Why: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

Option review:

A: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

B: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

D: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

Learning point: Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices

Question 7

Wide World Importers has already ruled out manual per-device administration. For the lab-device cohort, rollout wave 2, the remaining requirement is to block access to protected resources unless the device meets Intune compliance requirements. Which choice best addresses it?

  1. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  2. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  3. Configure Windows Hello for Business through Intune policy
  4. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  5. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices

Correct answer: D

Why: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.

Option review:

A: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

C: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

D: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.

E: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

Learning point: Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant

Question 8

During post-pilot review at Northwind Traders, the desktop engineer identifies a gap: the organization still needs to deploy Windows Hello for Business authentication settings to managed Windows endpoints. Which action should be added before the pilot ring, rollout wave 2 moves to production?

  1. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  2. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  3. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  4. Configure Windows Hello for Business through Intune policy
  5. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices

Correct answer: D

Why: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

Option review:

A: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

B: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

C: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

D: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

E: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

Learning point: Configure Windows Hello for Business through Intune policy

Question 9

The security administrator at Tailspin Toys is comparing several cloud-management options for a tenant consolidation. Which one directly enables the team to centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices for the production ring, rollout wave 2?

  1. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  2. Configure Windows Hello for Business through Intune policy
  3. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  4. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  5. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices

Correct answer: D

Why: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

Option review:

A: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

B: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

D: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

E: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

Learning point: Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed

Question 10

A security and operations workshop at Alpine Ski House defines the desired outcome as follows: centrally control which accounts are members of local Windows groups such as Administrators. Which implementation should be chosen for the executive-device cohort, rollout wave 2?

  1. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  2. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  3. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  4. Configure Windows Hello for Business through Intune policy
  5. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices

Correct answer: C

Why: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: centrally control which accounts are members of local Windows groups such as Administrators.

Option review:

A: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.

B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.

C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: centrally control which accounts are members of local Windows groups such as Administrators.

D: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.

E: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.

Learning point: Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices

Question 11

Which action best matches this technical purpose for the remote-user cohort, rollout wave 3: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met.

  1. Configure Windows Hello for Business through Intune policy
  2. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  3. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  4. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  5. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices

Correct answer: C

Why: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met..

Option review:

A: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met..

B: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met..

C: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met..

D: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met..

E: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met..

Learning point: Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices

Question 12

An administrator at Northwind Traders describes the needed capability this way: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. Which option should be associated with that requirement for the shared-device cohort, rollout wave 3?

  1. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  2. Configure Windows Hello for Business through Intune policy
  3. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  4. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  5. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant

Correct answer: E

Why: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy..

Option review:

A: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy..

B: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy..

C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy..

D: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy..

E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy..

Learning point: Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant

Question 13

During a design validation for the field-device cohort, rollout wave 3, Tailspin Toys documents the following behavior: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. Which endpoint-management feature or action is being described?

  1. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  2. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  3. Configure Windows Hello for Business through Intune policy
  4. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  5. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant

Correct answer: C

Why: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device..

Option review:

A: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device..

B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device..

C: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device..

D: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device..

E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device..

Learning point: Configure Windows Hello for Business through Intune policy

Question 14

The desktop engineer must identify the Microsoft endpoint-management capability that provides this function for the developer cohort, rollout wave 3: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. Which choice is correct?

  1. Configure Windows Hello for Business through Intune policy
  2. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  3. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  4. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  5. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices

Correct answer: B

Why: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation..

Option review:

A: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation..

B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation..

C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation..

D: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation..

E: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation..

Learning point: Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed

Question 15

A runbook for the frontline-user cohort, rollout wave 3 contains this description: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. Which implementation belongs in that runbook?

  1. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  2. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  3. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  4. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  5. Configure Windows Hello for Business through Intune policy

Correct answer: B

Why: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..

Option review:

A: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..

B: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..

C: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..

D: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..

E: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..

Learning point: Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices

Question 16

Northwind Traders is troubleshooting a branch migration. Evidence shows that the decisive requirement is to evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements. Which action should the Intune administrator investigate first for the kiosk cohort, rollout wave 4?

  1. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  2. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  3. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  4. Configure Windows Hello for Business through Intune policy
  5. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices

Correct answer: E

Why: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

Option review:

A: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

B: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

D: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

E: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

Learning point: Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices

Question 17

After eliminating network and licensing causes, the Microsoft 365 administrator at Tailspin Toys determines that success depends on the ability to block access to protected resources unless the device meets Intune compliance requirements. Which endpoint-management action should be checked next for the new-hire cohort, rollout wave 4?

  1. Configure Windows Hello for Business through Intune policy
  2. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  3. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  4. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  5. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant

Correct answer: E

Why: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.

Option review:

A: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

B: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

C: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

D: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.

Learning point: Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant

Question 18

A service-desk escalation during a operations review has been narrowed to one management requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints. Which configuration is the most relevant starting point for the contractor cohort, rollout wave 4?

  1. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  2. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  3. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  4. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  5. Configure Windows Hello for Business through Intune policy

Correct answer: E

Why: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

Option review:

A: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

D: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

E: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

Learning point: Configure Windows Hello for Business through Intune policy

Question 19

The failure pattern at Wide World Importers affects the lab-device cohort, rollout wave 4. Before making unrelated policy changes, the service desk lead needs a solution that will centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices. Which action is most directly relevant?

  1. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  2. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  3. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  4. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  5. Configure Windows Hello for Business through Intune policy

Correct answer: B

Why: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

Option review:

A: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

D: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

E: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

Learning point: Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed

Question 20

While investigating a Windows 11 rollout, Northwind Traders confirms the environment must centrally control which accounts are members of local Windows groups such as Administrators. Which Microsoft endpoint-management capability should be validated for the pilot ring, rollout wave 4?

  1. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  2. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  3. Configure Windows Hello for Business through Intune policy
  4. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  5. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant

Correct answer: A

Why: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: centrally control which accounts are members of local Windows groups such as Administrators.

Option review:

A: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: centrally control which accounts are members of local Windows groups such as Administrators.

B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.

C: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.

D: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.

E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.

Learning point: Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices

Question 21

Two teams at Tailspin Toys propose different approaches for the production ring, rollout wave 5. The selection criterion is simple: the chosen approach must evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements. Which option should win the technical comparison?

  1. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  2. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  3. Configure Windows Hello for Business through Intune policy
  4. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  5. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed

Correct answer: B

Why: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

Option review:

A: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

B: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

C: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

D: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

E: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

Learning point: Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices

Question 22

For the executive-device cohort, rollout wave 5, Alpine Ski House wants the least indirect solution to this goal: block access to protected resources unless the device meets Intune compliance requirements. Which action aligns most closely with that requirement?

  1. Configure Windows Hello for Business through Intune policy
  2. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  3. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  4. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  5. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed

Correct answer: B

Why: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.

Option review:

A: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

B: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.

C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

D: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

E: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

Learning point: Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant

Question 23

A modernization plan at Wide World Importers includes a tenant consolidation. The Microsoft 365 administrator is asked to choose the control that specifically helps the organization deploy Windows Hello for Business authentication settings to managed Windows endpoints. Which choice fits best for the remote-user cohort, rollout wave 5?

  1. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  2. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  3. Configure Windows Hello for Business through Intune policy
  4. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  5. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed

Correct answer: C

Why: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

Option review:

A: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

B: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

C: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

D: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

E: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

Learning point: Configure Windows Hello for Business through Intune policy

Question 24

The shared-device cohort, rollout wave 5 is moving into a controlled rollout at Northwind Traders. Which action should be included when the stated management objective is to centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices?

  1. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  2. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  3. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  4. Configure Windows Hello for Business through Intune policy
  5. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices

Correct answer: B

Why: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

Option review:

A: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

D: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

E: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

Learning point: Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed

Question 25

Tailspin Toys is replacing an ad hoc process during a application modernization. The replacement must reliably centrally control which accounts are members of local Windows groups such as Administrators. Which endpoint-management approach should the service desk lead implement for the field-device cohort, rollout wave 5?

  1. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  2. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  3. Configure Windows Hello for Business through Intune policy
  4. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  5. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant

Correct answer: A

Why: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: centrally control which accounts are members of local Windows groups such as Administrators.

Option review:

A: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: centrally control which accounts are members of local Windows groups such as Administrators.

B: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.

C: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.

D: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.

E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally control which accounts are members of local Windows groups such as Administrators.

Learning point: Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices

Question 26

An audit finding for the developer cohort, rollout wave 6 says the current process does not consistently evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements. Which Microsoft endpoint-management action most directly closes that gap?

  1. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  2. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  3. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  4. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  5. Configure Windows Hello for Business through Intune policy

Correct answer: A

Why: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

Option review:

A: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. This directly addresses the requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

D: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

E: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: evaluate Windows and non-Windows endpoints against platform-appropriate compliance requirements.

Learning point: Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices

Question 27

The security administrator at Wide World Importers needs a repeatable configuration for the frontline-user cohort, rollout wave 6. It must block access to protected resources unless the device meets Intune compliance requirements. Which choice should be implemented instead of relying on manual endpoint work?

  1. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  2. Configure Windows Hello for Business through Intune policy
  3. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  4. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  5. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices

Correct answer: A

Why: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.

Option review:

A: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. This directly addresses the requirement: block access to protected resources unless the device meets Intune compliance requirements.

B: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

D: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

E: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: block access to protected resources unless the device meets Intune compliance requirements.

Learning point: Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant

Question 28

During readiness testing at Northwind Traders, the kiosk cohort, rollout wave 6 fails a business requirement because administrators cannot yet deploy Windows Hello for Business authentication settings to managed Windows endpoints. Which action should be implemented before rollout continues?

  1. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  2. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  3. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  4. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  5. Configure Windows Hello for Business through Intune policy

Correct answer: E

Why: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

Option review:

A: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

B: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

D: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

E: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. This directly addresses the requirement: deploy Windows Hello for Business authentication settings to managed Windows endpoints.

Learning point: Configure Windows Hello for Business through Intune policy

Question 29

A governance review asks the Microsoft 365 administrator to justify the control selected for the new-hire cohort, rollout wave 6. The requirement is to centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices. Which action has the clearest technical alignment?

  1. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  2. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  3. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  4. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  5. Configure Windows Hello for Business through Intune policy

Correct answer: B

Why: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

Option review:

A: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. This directly addresses the requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

D: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

E: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally manage and rotate unique local administrator passwords on Microsoft Entra joined Windows devices.

Learning point: Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed

Question 30

For a security hardening project, Alpine Ski House needs an endpoint-management capability with this effect: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. Which option most accurately provides that capability for the contractor cohort, rollout wave 6?

  1. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  2. Configure Windows Hello for Business through Intune policy
  3. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  4. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  5. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant

Correct answer: C

Why: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..

Option review:

A: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..

B: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..

C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. This directly addresses the requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..

D: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..

E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint..

Learning point: Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices

Popular posts

img