Microsoft MD-102 Intune RBAC Scope Tags And Multi Admin Approval Practice Test

 

Skills 1.3 • 25 original questions

This Microsoft MD-102 Endpoint Administrator practice test focuses on intune rbac scope tags and multi admin approval through original scenario-based questions aligned to the skills measured as of July 24, 2026. Use the full ExamSnap MD-102 collection for broader practice across all current skill areas. For broader exam preparation, review the Microsoft MD-102 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

During a security hardening project at Adventure Works, the desktop engineer must delegate Intune or Windows 365 administration without granting broader permissions than necessary. Which action most directly satisfies the requirement? The affected devices are in the shared-device cohort, rollout wave 1.

  1. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  2. Configure Windows Hello for Business through Intune policy
  3. Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution
  4. Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator
  5. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant

Correct answer: D

Why: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. This directly addresses the requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

Option review:

A: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

B: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

C: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

D: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. This directly addresses the requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

Learning point: Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator

Question 2

Proseware Services is revising endpoint operations for a tenant consolidation. Administrators need to limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant. Which implementation should the security administrator select for the field-device cohort, rollout wave 1?

  1. Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage
  2. Configure Windows Hello for Business through Intune policy
  3. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  4. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  5. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices

Correct answer: A

Why: Scope tags help partition administration by controlling the objects visible within a role assignment. This directly addresses the requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

Option review:

A: Scope tags help partition administration by controlling the objects visible within a role assignment. This directly addresses the requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

B: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

C: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

D: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

E: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

Learning point: Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage

Question 3

A ticket escalated to the Intune administrator at Fourth Coffee states one non-negotiable goal: require a second administrator to approve selected high-impact Intune changes. Which choice is the strongest fit for the developer cohort, rollout wave 1?

  1. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  2. Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution
  3. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  4. Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage
  5. Configure Windows Hello for Business through Intune policy

Correct answer: B

Why: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. This directly addresses the requirement: require a second administrator to approve selected high-impact Intune changes.

Option review:

A: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

B: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. This directly addresses the requirement: require a second administrator to approve selected high-impact Intune changes.

C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

D: Scope tags help partition administration by controlling the objects visible within a role assignment. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

E: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

Learning point: Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution

Question 4

For the frontline-user cohort, rollout wave 2 at Fabrikam Retail, a compliance initiative can proceed only if the team can delegate Intune or Windows 365 administration without granting broader permissions than necessary. What should the endpoint administrator configure?

  1. Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution
  2. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  3. Configure Windows Hello for Business through Intune policy
  4. Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator
  5. Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage

Correct answer: D

Why: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. This directly addresses the requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

Option review:

A: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

B: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

C: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

D: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. This directly addresses the requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

E: Scope tags help partition administration by controlling the objects visible within a role assignment. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

Learning point: Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator

Question 5

The endpoint architecture review at Adventure Works focuses on this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant. Which Microsoft management action is most appropriate for the kiosk cohort, rollout wave 2?

  1. Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator
  2. Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage
  3. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  4. Configure Windows Hello for Business through Intune policy
  5. Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution

Correct answer: B

Why: Scope tags help partition administration by controlling the objects visible within a role assignment. This directly addresses the requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

Option review:

A: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

B: Scope tags help partition administration by controlling the objects visible within a role assignment. This directly addresses the requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

D: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

E: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

Learning point: Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage

Question 6

A change advisory board at Proseware Services asks how to require a second administrator to approve selected high-impact Intune changes during a BYOD program. Which proposed action should the service desk lead approve for the new-hire cohort, rollout wave 2?

  1. Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution
  2. Configure Windows Hello for Business through Intune policy
  3. Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage
  4. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  5. Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator

Correct answer: A

Why: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. This directly addresses the requirement: require a second administrator to approve selected high-impact Intune changes.

Option review:

A: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. This directly addresses the requirement: require a second administrator to approve selected high-impact Intune changes.

B: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

C: Scope tags help partition administration by controlling the objects visible within a role assignment. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

D: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

E: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

Learning point: Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution

Question 7

Fourth Coffee has already ruled out manual per-device administration. For the contractor cohort, rollout wave 3, the remaining requirement is to delegate Intune or Windows 365 administration without granting broader permissions than necessary. Which choice best addresses it?

  1. Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator
  2. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  3. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  4. Configure Windows Hello for Business through Intune policy
  5. Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage

Correct answer: A

Why: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. This directly addresses the requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

Option review:

A: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. This directly addresses the requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

B: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

C: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

D: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

E: Scope tags help partition administration by controlling the objects visible within a role assignment. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

Learning point: Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator

Question 8

During post-pilot review at Fabrikam Retail, the security administrator identifies a gap: the organization still needs to limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant. Which action should be added before the lab-device cohort, rollout wave 3 moves to production?

  1. Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution
  2. Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage
  3. Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator
  4. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  5. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed

Correct answer: B

Why: Scope tags help partition administration by controlling the objects visible within a role assignment. This directly addresses the requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

Option review:

A: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

B: Scope tags help partition administration by controlling the objects visible within a role assignment. This directly addresses the requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

C: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

D: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

E: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

Learning point: Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage

Question 9

The Intune administrator at Adventure Works is comparing several cloud-management options for a branch migration. Which one directly enables the team to require a second administrator to approve selected high-impact Intune changes for the pilot ring, rollout wave 3?

  1. Configure Windows Hello for Business through Intune policy
  2. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  3. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  4. Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution
  5. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices

Correct answer: D

Why: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. This directly addresses the requirement: require a second administrator to approve selected high-impact Intune changes.

Option review:

A: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

D: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. This directly addresses the requirement: require a second administrator to approve selected high-impact Intune changes.

E: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

Learning point: Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution

Question 10

A security and operations workshop at Proseware Services defines the desired outcome as follows: delegate Intune or Windows 365 administration without granting broader permissions than necessary. Which implementation should be chosen for the production ring, rollout wave 4?

  1. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  2. Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator
  3. Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage
  4. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  5. Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution

Correct answer: B

Why: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. This directly addresses the requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

Option review:

A: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

B: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. This directly addresses the requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

C: Scope tags help partition administration by controlling the objects visible within a role assignment. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

D: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

E: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

Learning point: Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator

Question 11

Which action best matches this technical purpose for the executive-device cohort, rollout wave 4: Scope tags help partition administration by controlling the objects visible within a role assignment.

  1. Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage
  2. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  3. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  4. Configure Windows Hello for Business through Intune policy
  5. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices

Correct answer: A

Why: Scope tags help partition administration by controlling the objects visible within a role assignment. This directly addresses the requirement: Scope tags help partition administration by controlling the objects visible within a role assignment..

Option review:

A: Scope tags help partition administration by controlling the objects visible within a role assignment. This directly addresses the requirement: Scope tags help partition administration by controlling the objects visible within a role assignment..

B: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Scope tags help partition administration by controlling the objects visible within a role assignment..

C: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Scope tags help partition administration by controlling the objects visible within a role assignment..

D: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Scope tags help partition administration by controlling the objects visible within a role assignment..

E: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Scope tags help partition administration by controlling the objects visible within a role assignment..

Learning point: Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage

Question 12

An administrator at Fabrikam Retail describes the needed capability this way: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. Which option should be associated with that requirement for the remote-user cohort, rollout wave 4?

  1. Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution
  2. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  3. Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage
  4. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  5. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices

Correct answer: A

Why: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. This directly addresses the requirement: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator..

Option review:

A: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. This directly addresses the requirement: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator..

B: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator..

C: Scope tags help partition administration by controlling the objects visible within a role assignment. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator..

D: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator..

E: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator..

Learning point: Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution

Question 13

During a design validation for the shared-device cohort, rollout wave 5, Adventure Works documents the following behavior: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. Which endpoint-management feature or action is being described?

  1. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  2. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  3. Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator
  4. Configure Windows Hello for Business through Intune policy
  5. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed

Correct answer: C

Why: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. This directly addresses the requirement: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities..

Option review:

A: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities..

B: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities..

C: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. This directly addresses the requirement: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities..

D: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities..

E: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities..

Learning point: Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator

Question 14

The security administrator must identify the Microsoft endpoint-management capability that provides this function for the field-device cohort, rollout wave 5: Scope tags help partition administration by controlling the objects visible within a role assignment. Which choice is correct?

  1. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  2. Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution
  3. Configure Windows Hello for Business through Intune policy
  4. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  5. Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage

Correct answer: E

Why: Scope tags help partition administration by controlling the objects visible within a role assignment. This directly addresses the requirement: Scope tags help partition administration by controlling the objects visible within a role assignment..

Option review:

A: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Scope tags help partition administration by controlling the objects visible within a role assignment..

B: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Scope tags help partition administration by controlling the objects visible within a role assignment..

C: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Scope tags help partition administration by controlling the objects visible within a role assignment..

D: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Scope tags help partition administration by controlling the objects visible within a role assignment..

E: Scope tags help partition administration by controlling the objects visible within a role assignment. This directly addresses the requirement: Scope tags help partition administration by controlling the objects visible within a role assignment..

Learning point: Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage

Question 15

A runbook for the developer cohort, rollout wave 5 contains this description: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. Which implementation belongs in that runbook?

  1. Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage
  2. Configure Windows Hello for Business through Intune policy
  3. Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution
  4. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  5. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed

Correct answer: C

Why: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. This directly addresses the requirement: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator..

Option review:

A: Scope tags help partition administration by controlling the objects visible within a role assignment. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator..

B: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator..

C: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. This directly addresses the requirement: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator..

D: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator..

E: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator..

Learning point: Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution

Question 16

Fabrikam Retail is troubleshooting a compliance initiative. Evidence shows that the decisive requirement is to delegate Intune or Windows 365 administration without granting broader permissions than necessary. Which action should the Microsoft 365 administrator investigate first for the frontline-user cohort, rollout wave 6?

  1. Configure Windows Hello for Business through Intune policy
  2. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  3. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  4. Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator
  5. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices

Correct answer: D

Why: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. This directly addresses the requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

Option review:

A: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

B: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

C: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

D: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. This directly addresses the requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

E: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

Learning point: Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator

Question 17

After eliminating network and licensing causes, the endpoint administrator at Adventure Works determines that success depends on the ability to limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant. Which endpoint-management action should be checked next for the kiosk cohort, rollout wave 6?

  1. Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator
  2. Configure Windows Hello for Business through Intune policy
  3. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  4. Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage
  5. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices

Correct answer: D

Why: Scope tags help partition administration by controlling the objects visible within a role assignment. This directly addresses the requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

Option review:

A: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

B: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

D: Scope tags help partition administration by controlling the objects visible within a role assignment. This directly addresses the requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

E: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

Learning point: Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage

Question 18

A service-desk escalation during a BYOD program has been narrowed to one management requirement: require a second administrator to approve selected high-impact Intune changes. Which configuration is the most relevant starting point for the new-hire cohort, rollout wave 6?

  1. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  2. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  3. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  4. Configure Windows Hello for Business through Intune policy
  5. Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution

Correct answer: E

Why: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. This directly addresses the requirement: require a second administrator to approve selected high-impact Intune changes.

Option review:

A: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

B: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

C: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

D: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

E: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. This directly addresses the requirement: require a second administrator to approve selected high-impact Intune changes.

Learning point: Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution

Question 19

The failure pattern at Fourth Coffee affects the contractor cohort, rollout wave 7. Before making unrelated policy changes, the desktop engineer needs a solution that will delegate Intune or Windows 365 administration without granting broader permissions than necessary. Which action is most directly relevant?

  1. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  2. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  3. Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator
  4. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  5. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant

Correct answer: C

Why: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. This directly addresses the requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

Option review:

A: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

B: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

C: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. This directly addresses the requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

D: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

Learning point: Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator

Question 20

While investigating a tenant consolidation, Fabrikam Retail confirms the environment must limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant. Which Microsoft endpoint-management capability should be validated for the lab-device cohort, rollout wave 7?

  1. Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator
  2. Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage
  3. Configure Windows Hello for Business through Intune policy
  4. Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution
  5. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant

Correct answer: B

Why: Scope tags help partition administration by controlling the objects visible within a role assignment. This directly addresses the requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

Option review:

A: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

B: Scope tags help partition administration by controlling the objects visible within a role assignment. This directly addresses the requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

C: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

D: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

E: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

Learning point: Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage

Question 21

Two teams at Adventure Works propose different approaches for the pilot ring, rollout wave 7. The selection criterion is simple: the chosen approach must require a second administrator to approve selected high-impact Intune changes. Which option should win the technical comparison?

  1. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  2. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  3. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  4. Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution
  5. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed

Correct answer: D

Why: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. This directly addresses the requirement: require a second administrator to approve selected high-impact Intune changes.

Option review:

A: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

B: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

C: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

D: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. This directly addresses the requirement: require a second administrator to approve selected high-impact Intune changes.

E: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

Learning point: Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution

Question 22

For the production ring, rollout wave 8, Proseware Services wants the least indirect solution to this goal: delegate Intune or Windows 365 administration without granting broader permissions than necessary. Which action aligns most closely with that requirement?

  1. Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution
  2. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  3. Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage
  4. Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator
  5. Configure Windows Hello for Business through Intune policy

Correct answer: D

Why: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. This directly addresses the requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

Option review:

A: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

B: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

C: Scope tags help partition administration by controlling the objects visible within a role assignment. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

D: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. This directly addresses the requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

E: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

Learning point: Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator

Question 23

A modernization plan at Fourth Coffee includes a Windows 11 rollout. The endpoint administrator is asked to choose the control that specifically helps the organization limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant. Which choice fits best for the executive-device cohort, rollout wave 8?

  1. Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage
  2. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  3. Configure Windows LAPS policy in Intune and store/rotate local administrator passwords through Microsoft Entra ID as designed
  4. Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator
  5. Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution

Correct answer: A

Why: Scope tags help partition administration by controlling the objects visible within a role assignment. This directly addresses the requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

Option review:

A: Scope tags help partition administration by controlling the objects visible within a role assignment. This directly addresses the requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

B: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

C: Windows LAPS manages unique local administrator passwords and can back them up to Microsoft Entra ID for controlled recovery and rotation. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

D: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

E: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: limit an Intune administrator to a defined set of devices, apps, or policies in a multi-admin tenant.

Learning point: Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage

Question 24

The remote-user cohort, rollout wave 8 is moving into a controlled rollout at Fabrikam Retail. Which action should be included when the stated management objective is to require a second administrator to approve selected high-impact Intune changes?

  1. Apply scope tags and scoped role assignments to limit which Intune objects an administrator can see and manage
  2. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  3. Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution
  4. Create a Microsoft Entra Conditional Access policy that requires the device to be marked compliant
  5. Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator

Correct answer: C

Why: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. This directly addresses the requirement: require a second administrator to approve selected high-impact Intune changes.

Option review:

A: Scope tags help partition administration by controlling the objects visible within a role assignment. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

B: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

C: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. This directly addresses the requirement: require a second administrator to approve selected high-impact Intune changes.

D: Conditional Access can use the Intune compliance result as an access condition so noncompliant devices cannot satisfy the policy. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

E: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: require a second administrator to approve selected high-impact Intune changes.

Learning point: Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution

Question 25

Adventure Works is replacing an ad hoc process during a security hardening project. The replacement must reliably delegate Intune or Windows 365 administration without granting broader permissions than necessary. Which endpoint-management approach should the desktop engineer implement for the shared-device cohort, rollout wave 9?

  1. Use Intune account protection/local user group membership policy to control membership of local groups on Windows devices
  2. Create Intune compliance policies for the supported platforms and assign them to the appropriate users or devices
  3. Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator
  4. Configure Windows Hello for Business through Intune policy
  5. Configure multi-admin approval for sensitive Intune changes that require a second administrator to approve before execution

Correct answer: C

Why: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. This directly addresses the requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

Option review:

A: Intune can manage local group membership so privileged local groups are configured consistently without manual changes on each endpoint. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

B: Compliance policies evaluate device state against organizational requirements and can report or mark devices noncompliant when requirements are not met. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

C: Role-based access control limits administrative capabilities so operators receive only the permissions needed for their responsibilities. This directly addresses the requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

D: Windows Hello for Business provides phishing-resistant key- or certificate-backed authentication tied to the user and device. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

E: Multi-admin approval introduces separation of duties for selected administrative actions by requiring approval from another authorized administrator. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: delegate Intune or Windows 365 administration without granting broader permissions than necessary.

Learning point: Assign the least-privilege built-in or custom Intune/Windows 365 role required for the administrator

Popular posts

img