Exam MD-102 All QuestionsBrowse all questions from this exam
Question 112

You have a Microsoft 365 subscription that contains a user named User1 and uses Microsoft Intune Suite.

You use Microsoft Intune to manage devices that run Windows 11.

User provides remote support for 75 devices in the marketing department.

You need to add User1 to the Remote Desktop Users group on each marketing department device.

What should you configure?

    Correct Answer: C

    To add a user to the Remote Desktop Users group on each marketing department device managed by Microsoft Intune, you should configure an account protection policy. The account protection policy allows you to manage local user group memberships on Windows devices, including adding specific users to groups such as the Remote Desktop Users group.

Discussion
Fortind1974Option: C

C. an account protection policy https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-security-account-protection-policy#manage-local-groups-on-windows-devices

Krayzr

You are correct Sir Local user group membership (preview) – Use this profile to add, remove, or replace members of the built-in local groups on Windows devices. For example, the Administrators local group has broad rights. You can use this policy to edit the Admin group's membership to lock it down to a set of exclusively defined members.

ronnykingsOption: D

Accorrding to Bing Chat the correct answer is D: a a device configuration profile

yoha1558

verify with the url https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-security-account-protection-policy#manage-local-groups-on-windows-devices you check it's C

KrayzrOption: C

C is correct Still in preview, but Tried in my tenant https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-security-account-protection-policy#manage-local-groups-on-windows-devices

oopspruuOption: C

Account Protection section in Endpoint Security has the policy for exactly this purpose. We use this to create users in local Admin groups when making LAPS policies.

PrasisOption: D

D To add User1 to the Remote Desktop Users group on each marketing department device, you should configure a device configuration profile. Device configuration profiles in Microsoft Intune allow you to define and push settings to managed devices. In this case, you can use a device configuration profile to manage the built-in group memberships on devices, including the Remote Desktop Users group. This will allow User1 to provide remote support for the devices in the marketing department.

CJL324Option: D

D. A device configuration profile in Intune allows you to manage settings and configurations on the devices, including adding users to specific local groups such as the Remote Desktop Users group. You can create a custom profile to automate this task across all the relevant devices.

Dave808Option: D

D is the answer To add User1 to the Remote Desktop Users group on each marketing department device running Windows 11, you should configure a device configuration profile. This profile allows you to manage settings and configurations on devices enrolled in Microsoft Intune. Here’s how you can achieve this using PowerShell: Manual Process: Open Computer Management. Click the Action menu. Select Connect to Another Computer. Type the Computer Name (e.g., “Computer1”). Click OK. Expand Local Users and Groups

MR_EliotOption: C

c is correct

DarkfireOption: C

Should be C idd. https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-security-account-protection-policy#:~:text=Local%20user%20group%20membership%20(preview)%20%E2%80%93%20Use,Manage%20local%20groups%20on%20Windows%20devices.

MerrybobOption: C

C. an account protection policy Ref: https://learn.microsoft.com/en-us/entra/identity/devices/assign-local-admin#manage-administrator-privileges-using-microsoft-entra-groups-preview:~:text=Organizations%20can%20use%20Intune%20to%20manage%20these%20policies%20using%20Custom%20OMA%2DURI%20Settings%20or%20Account%20protection%20policy.

mp34

I thought if a topic was in preview then it would not be on the exam....the link provided by Fortind1974 says it is still in preview...

Amir1909Option: C

C is correct

MenoviceOption: C

C is correct. Enabling Remote Desktop: Creating Configuration Profile Adding Users to Remote Desktop: Account Protection

Sonia33Option: C

It must be account protection policy. That allows you add users to local groups.

chandravamsiOption: D

D is correct

NoursBearOption: D

It can be done with a configuration profile setting but there are more steps: https://www.petervanderwoude.nl/post/enabling-remote-access-for-specific-users-on-azure-ad-joined-devices/ Account protection under Endpoint Security seems to correct one though

ITCALegendsOption: C

Dont even fully understand the question but C is correct as others dont apply