MD-102 Exam QuestionsBrowse all questions from this exam

MD-102 Exam - Question 142


Your network contains an Active Directory domain. The domain contains 2,000 computers that run Windows 10.

You implement hybrid Azure AD and Microsoft Intune.

You need to automatically register all the existing computers to Azure AD and enroll the computers in Intune. The solution must minimize administrative effort.

What should you use?

Show Answer
Correct Answer: B,D

To automatically register all existing computers to Azure AD and enroll them in Intune with minimal administrative effort, you should use a Group Policy object (GPO). A GPO can enable automatic MDM enrollment using default Azure AD credentials and configure the MDM user scope. This allows for centralized management and streamlined deployment without the need for individual configuration on each device. Autodiscover address records and service connection points are related to Exchange and not relevant here, while Windows Autopilot is more suited for new device setups rather than existing ones.

Discussion

17 comments
Sign in to comment
Fortind1974Option: B
Sep 9, 2023

B. a Group Policy object (GPO) https://learn.microsoft.com/en-us/windows/client-management/enroll-a-windows-10-device-automatically-using-group-policy

h38jhd38kOption: D
Oct 22, 2023

It is a trick question because least administrative is Windows Autopilot which would reset the devices. If resetting the device is a concern then it would GPO. Hopefully the exam isn't as vague as this question is

VirtualJPOption: B
Oct 17, 2023

Agreed

BJS78Option: B
Sep 26, 2023

GPO and Autopilot both can do it, but as we migrate prod devices, it is quite possible we don't want to reset the devices, so this way "B" is better.

chandravamsiOption: B
Nov 8, 2023

Group policy Object

chandravamsiOption: D
Nov 12, 2023

Optin: D

yosryOption: B
Dec 24, 2023

B IS CORRECT

yosryOption: B
Jan 2, 2024

B IS CORRECT

Amir1909Option: B
Jan 10, 2024

B is correct

KrayzrOption: B
Jan 20, 2024

The answer is B. a Group Policy object (GPO).

Krayzr
Jan 20, 2024

Here's why: GPOs are the most efficient way to automate registration and enrollment for existing devices in a hybrid Azure AD environment. They allow you to apply settings to a large number of devices centrally, minimizing the administrative effort involved. Here's how it works: Create a GPO: Use the Group Policy Management Console (GPMC) to create a new GPO that targets the computers you want to enroll. Enable automatic MDM enrollment: Within the GPO, enable the policy setting for "Enable automatic MDM enrollment using default Azure AD credentials." Configure MDM user scope: Specify whether the enrollment applies to all users or a specific group of users. Apply the GPO: Link the GPO to the appropriate Active Directory organizational unit (OU) to apply it to the targeted computers.

Krayzr
Jan 20, 2024

Once the GPO is applied, computers will automatically register with Azure AD and enroll in Intune when users sign in with their Azure AD credentials. Why the other options are not suitable: Autodiscover address record and Autodiscover service connection point (SCP): These are used for discovering Exchange server settings in Outlook clients, not for device registration or enrollment. Windows Autopilot deployment profile: This is used for streamlining the setup of new devices, not for managing existing devices.

PasadoOption: D
Feb 7, 2024

ChatGPT: To automatically register all existing computers to Azure AD and enroll them in Intune with minimal administrative effort, you should use **Windows Autopilot deployment profile** (option D). Autopilot allows you to pre-register devices with Azure AD and enroll them in Intune as part of the out-of-box experience for end-users. This helps streamline the deployment process and reduces the need for manual intervention.

sergioandreslq
Mar 6, 2024

ChatGPT is lost in the answer, instead of just copy paste ChatGPT's answer, I recommend you analyze it a little bit more the answer before publishing it here, This kind of answer just adds noise to people you are trying to add value why the answer.

MR_EliotOption: B
Mar 3, 2024

Correct answer is C. Key is lease administrative effort!!! https://youtu.be/Q15ZXyvzQfs?si=8Am2s2H-qN2TtvLa

MR_Eliot
Mar 3, 2024

Answer is C!

KrayzrOption: B
Feb 12, 2024

B. a Group Policy object (GPO)

mhmyzOption: C
Mar 13, 2024

I think SCP is most simple way.I have experience configuring it. https://learn.microsoft.com/en-us/entra/identity/devices/how-to-hybrid-join The second method is GPO. Used when joining partial devices to Hybrid AD.

TMpicsOption: B
Mar 22, 2024

B. a Group Policy object (GPO) Correct

CJL324Option: B
May 17, 2024

B. a Group Policy object (GPO). You can create and deploy a Group Policy object (GPO) that configures the devices for hybrid Azure AD join and Intune enrollment. This GPO can include settings such as enabling hybrid Azure AD join and configuring automatic enrollment in Intune. Once applied, the GPO will automatically register all existing computers to Azure AD and enroll them in Intune, ensuring they are properly managed without requiring manual intervention on each device.

oopspruuOption: B
Jul 21, 2024

the GPO policy can hybrid join existing devices to Intune without resetting. That has been the standard practice when you want to go from fully on-prem to Intune managed.