MD-102 Exam QuestionsBrowse all questions from this exam

MD-102 Exam - Question 180


You have an Azure AD tenant named contoso.com.

You need to ensure that users are not added automatically to the local Administrators group when they join their Windows 11 device to contoso.com.

What should you configure?

Show Answer
Correct Answer: D

To ensure that users are not added automatically to the local Administrators group when they join their Windows 11 device to contoso.com, you should configure the Device settings in Azure AD. Device settings in Azure AD allow you to control policies related to device enrollment and management, including settings that restrict local administrator access during the enrollment process.

Discussion

17 comments
Sign in to comment
yoha1558Option: A
Oct 25, 2023

in Autopilot, you choose the type of user Administrator or Standard.

belyoOption: A
Dec 19, 2023

If you want to prevent regular users from becoming local administrators, you have the following options: Windows Autopilot & bulk enrollment https://learn.microsoft.com/en-us/entra/identity/devices/assign-local-admin#manage-regular-users

3661de6Option: D
Apr 8, 2024

D. entra.microsoft.com -> device setting -> Select No under "Registering user is added as local administrator on the device during Microsoft Entra join" The question doesn't mention Autopilot

MJFTOption: D
Apr 12, 2024

https://learn.microsoft.com/en-us/entra/identity/devices/howto-manage-local-admin-passwords Enabling Windows LAPS with Microsoft Entra ID

LiamAzure
Nov 4, 2023

"When they join their device" Does this mean Autopilot is not being used, since they are manually adding their device. Or am I reading too much into it Its A or D depending on what microsoft is looking for

GavrilGOption: D
Dec 2, 2023

The correct answer is D. Device settings in Azure AD. To prevent users from being added automatically to the local Administrators group when they join their Windows 11 device to contoso.com, you need to configure the Device settings in Azure AD.

yosryOption: A
Dec 17, 2023

correct

Amir1909
Jan 10, 2024

Correct

Mattia8Option: A
Jan 17, 2024

Correct

mp34Option: A
Jan 23, 2024

There is a setting in Autopilot deployment profile to set either a Standard or Administrator user.....but the question doesnt mention adding devices to Intune...so why Autopilot?

PasadoOption: B
Feb 4, 2024

ChatGPT answer is B. Provisioning packages for Windows.

VLAG
Feb 27, 2024

ChatGPT is useful but it gives wrong answers when it is used in a wrong way. Here's "A"

MR_EliotOption: A
Mar 9, 2024

A is correct.

ejonesy80Option: A
Apr 17, 2024

Right Answer = A Manage regular users: By default, Microsoft Entra ID adds the user performing the Microsoft Entra join to the administrator group on the device. If you want to prevent regular users from becoming local administrators, you have the following options: Windows Autopilot - Windows Autopilot provides you with an option to prevent primary user performing the join from becoming a local administrator by creating an Autopilot profile. Bulk enrollment - a Microsoft Entra join that is performed in the context of a bulk enrollment happens in the context of an autocreated user. Users signing in after a device has been joined aren't added to the administrators group. Source: https://learn.microsoft.com/en-us/entra/identity/devices/assign-local-admin#manage-regular-users

62b396dOption: D
Apr 18, 2024

doesnt say anything about autopilot. it says "when user joins". wouldn't that be D? If they never go through autopilot, then Autopilot profile won't do anything.

62b396dOption: D
Apr 18, 2024

Doesn't say anything about autopilot, just that a user joins their device. so D, Device Settings.

CJL324Option: D
May 18, 2024

D. Device settings in Azure AD. Device settings in Azure AD allow you to configure policies that control device behavior, including settings related to device enrollment and management. You can use these settings to configure restrictions on local administrator access to devices enrolled in Azure AD.

CJL324
May 18, 2024

Option A, Windows Autopilot, primarily focuses on simplifying the deployment and management of Windows devices, including Windows 11 devices, through cloud-based services. While Windows Autopilot offers various configuration options for device provisioning and enrollment, it does not directly control the membership of local groups on devices. Configuring Windows Autopilot might not directly address the requirement to prevent users from being added automatically to the local Administrators group on Windows 11 devices joined to the contoso.com Azure AD tenant. Therefore, while Windows Autopilot can play a role in device provisioning and enrollment, it may not be the most appropriate choice for addressing the specific requirement stated in the scenario.

chafeOption: D
Jul 13, 2024

Checked in tenant and ability to restrict local admin privs to some, all or none is present in device settings as preview. Was added ~March '24, the longer you are reading this from now the more likely it is to be right. I still favour D as the question doesn't mention Autopilot, and if you go the autopilot route everyone's device is getting reset.