MD-102 Exam QuestionsBrowse all questions from this exam

MD-102 Exam - Question 272


You have a Microsoft 365 E5 subscription that includes Microsoft Intune and contains a user named Admin1.

Admin1 must use the Microsoft Intune admin center to perform the following tasks:

• Create and assign apps and policies to users and devices by using Intune.

• Create, assign, and delete Windows 365 Cloud PC provisioning policies.

You need to assign the required roles to Admin1. The solution must meet the following requirements:

• Follow the principle of least privilege.

• Minimize administrative effort.

What should you do?

Show Answer
Correct Answer: E

To meet the specified requirements, Admin1 needs the capability to create and assign apps and policies using Intune as well as manage Windows 365 Cloud PC provisioning policies. A built-in role like Cloud PC Administrator alone does not allow app and policy assignment with Intune. Since none of the built-in roles sufficiently cover both sets of tasks, creating a custom Intune role is necessary to provide Admin1 with the precise permissions needed while adhering to the principle of least privilege and minimizing administrative effort.

Discussion

2 comments
Sign in to comment
chafeOption: E
Jul 13, 2024

https://learn.microsoft.com/en-us/mem/intune/fundamentals/role-based-access-control None of the built in roles can satisfy both requirements, answer is correct

jdr002Option: E
Jul 14, 2024

Answer is correct "E". Cloud PC admin doesn't have the capability to assign applications. https://learn.microsoft.com/en-us/windows-365/enterprise/role-based-access