exam questions

Exam MD-102 All Questions

View all questions & answers for the MD-102 exam

Exam MD-102 topic 1 question 180 discussion

Actual exam question from Microsoft's MD-102
Question #: 180
Topic #: 1
[All MD-102 Questions]

You have an Azure AD tenant named contoso.com.

You need to ensure that users are not added automatically to the local Administrators group when they join their Windows 11 device to contoso.com.

What should you configure?

  • A. Windows Autopilot
  • B. provisioning packages for Windows
  • C. Security defaults in Azure AD
  • D. Device settings in Azure AD
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Tr619899
Highly Voted 8 months, 2 weeks ago
Selected Answer: D
To ensure that users are not added automatically to the local Administrators group when they join their Windows 11 device to Azure AD, you should configure Device settings in Azure AD. Specifically, you need to disable the setting that automatically adds users to the local Administrators group on Azure AD-joined devices. This can be done by setting Local Administrator Group Membership to None in Azure AD's device settings. Entra ID > Devices > Devices Settings > Under Local Administration Settings, Change the state to NONE for "Registering user is added as local administrator on the device during Microsoft Entra join (Preview)"
upvoted 14 times
...
yoha1558
Highly Voted 1 year, 9 months ago
Selected Answer: A
in Autopilot, you choose the type of user Administrator or Standard.
upvoted 12 times
...
theptr
Most Recent 3 weeks, 4 days ago
Selected Answer: A
You can config this in autopilot
upvoted 1 times
...
Aslan
3 months, 2 weeks ago
Selected Answer: D
Tested in a lab.
upvoted 2 times
...
sorinaccio
5 months, 3 weeks ago
Selected Answer: A
If you want to prevent regular users from becoming local administrators, you have the following options: Windows Autopilot & bulk enrollment https://learn.microsoft.com/en-us/entra/identity/devices/assign-local-admin#manage-regular-users
upvoted 1 times
Knight_Of_Peace
5 months, 3 weeks ago
You are right but the question is asking about Azure AD join and not Intune enrollment. Thus the correct answer is D. Entra ID > Devices > Devices Settings > Under Local Administration Settings, Change the state to NONE for "Registering user is added as local administrator on the device during Microsoft Entra join (Preview)"
upvoted 2 times
...
...
Alboo007_rs007
8 months, 2 weeks ago
Selected Answer: D
Correct Answer is D ...
upvoted 1 times
...
Pisces225
8 months, 3 weeks ago
Selected Answer: A
Only Autopilot prevents the auto join. The people saying D are referencing how to update the local admin after the fact. Using the method referenced in the link has no effect on the automatic addition of the user joining the device, that has to be done in Autopilot.
upvoted 1 times
...
AleFCI1908
9 months, 1 week ago
Selected Answer: D
D - https://learn.microsoft.com/en-us/entra/identity/devices/assign-local-admin#manage-the-microsoft-entra-joined-device-local-administrator-role
upvoted 2 times
...
bigreg
11 months ago
Selected Answer: D
Identity > Devices > Overview > Device settings
upvoted 1 times
bigreg
11 months ago
I changed my mind, I thinks its A now. Windows Autopilot - Windows Autopilot provides you with an option to prevent primary user performing the join from becoming a local administrator by creating an Autopilot profile. I hate how this is worded.
upvoted 2 times
FemiA55
8 months ago
The question is at Entra id join level. Way before Intune & Autopilot. Correct answer is: D
upvoted 1 times
...
Pisces225
8 months, 3 weeks ago
Correct. The question asks how to prevent them from ever having been added as a local admin to begin with.
upvoted 1 times
...
...
...
EUC_PRO
11 months, 1 week ago
Selected Answer: D
Confired. It is D - https://learn.microsoft.com/en-us/entra/identity/devices/assign-local-admin#manage-the-microsoft-entra-joined-device-local-administrator-role
upvoted 2 times
...
Cezt
1 year ago
Selected Answer: D
You can Join the devices i n many ways not just autopilot D
upvoted 3 times
...
oopspruu
1 year ago
Selected Answer: D
Entra Device Settings > Registering user is added as local administrator on the device during Microsoft Entra join (Preview) Technically, A can achieve this too. The question didn't specify if its during OOBE or for Autopilot. So the vagueness makes me incline towards D.
upvoted 2 times
...
chafe
1 year, 1 month ago
Selected Answer: D
Checked in tenant and ability to restrict local admin privs to some, all or none is present in device settings as preview. Was added ~March '24, the longer you are reading this from now the more likely it is to be right. I still favour D as the question doesn't mention Autopilot, and if you go the autopilot route everyone's device is getting reset.
upvoted 1 times
...
CJL324
1 year, 2 months ago
D. Device settings in Azure AD. Device settings in Azure AD allow you to configure policies that control device behavior, including settings related to device enrollment and management. You can use these settings to configure restrictions on local administrator access to devices enrolled in Azure AD.
upvoted 1 times
CJL324
1 year, 2 months ago
Option A, Windows Autopilot, primarily focuses on simplifying the deployment and management of Windows devices, including Windows 11 devices, through cloud-based services. While Windows Autopilot offers various configuration options for device provisioning and enrollment, it does not directly control the membership of local groups on devices. Configuring Windows Autopilot might not directly address the requirement to prevent users from being added automatically to the local Administrators group on Windows 11 devices joined to the contoso.com Azure AD tenant. Therefore, while Windows Autopilot can play a role in device provisioning and enrollment, it may not be the most appropriate choice for addressing the specific requirement stated in the scenario.
upvoted 1 times
...
...
62b396d
1 year, 3 months ago
Selected Answer: D
Doesn't say anything about autopilot, just that a user joins their device. so D, Device Settings.
upvoted 2 times
...
62b396d
1 year, 3 months ago
doesnt say anything about autopilot. it says "when user joins". wouldn't that be D? If they never go through autopilot, then Autopilot profile won't do anything.
upvoted 1 times
...
ejonesy80
1 year, 4 months ago
Right Answer = A Manage regular users: By default, Microsoft Entra ID adds the user performing the Microsoft Entra join to the administrator group on the device. If you want to prevent regular users from becoming local administrators, you have the following options: Windows Autopilot - Windows Autopilot provides you with an option to prevent primary user performing the join from becoming a local administrator by creating an Autopilot profile. Bulk enrollment - a Microsoft Entra join that is performed in the context of a bulk enrollment happens in the context of an autocreated user. Users signing in after a device has been joined aren't added to the administrators group. Source: https://learn.microsoft.com/en-us/entra/identity/devices/assign-local-admin#manage-regular-users
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...