exam questions

Exam MD-102 All Questions

View all questions & answers for the MD-102 exam

Exam MD-102 topic 1 question 180 discussion

Actual exam question from Microsoft's MD-102
Question #: 180
Topic #: 1
[All MD-102 Questions]

You have an Azure AD tenant named contoso.com.

You need to ensure that users are not added automatically to the local Administrators group when they join their Windows 11 device to contoso.com.

What should you configure?

  • A. Windows Autopilot
  • B. provisioning packages for Windows
  • C. Security defaults in Azure AD
  • D. Device settings in Azure AD
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Tr619899
Highly Voted 6 months ago
Selected Answer: D
To ensure that users are not added automatically to the local Administrators group when they join their Windows 11 device to Azure AD, you should configure Device settings in Azure AD. Specifically, you need to disable the setting that automatically adds users to the local Administrators group on Azure AD-joined devices. This can be done by setting Local Administrator Group Membership to None in Azure AD's device settings. Entra ID > Devices > Devices Settings > Under Local Administration Settings, Change the state to NONE for "Registering user is added as local administrator on the device during Microsoft Entra join (Preview)"
upvoted 14 times
...
yoha1558
Highly Voted 1 year, 7 months ago
Selected Answer: A
in Autopilot, you choose the type of user Administrator or Standard.
upvoted 11 times
...
Aslan
Most Recent 1 month ago
Selected Answer: D
Tested in a lab.
upvoted 2 times
...
sorinaccio
3 months, 1 week ago
Selected Answer: A
If you want to prevent regular users from becoming local administrators, you have the following options: Windows Autopilot & bulk enrollment https://learn.microsoft.com/en-us/entra/identity/devices/assign-local-admin#manage-regular-users
upvoted 1 times
Knight_Of_Peace
3 months, 1 week ago
You are right but the question is asking about Azure AD join and not Intune enrollment. Thus the correct answer is D. Entra ID > Devices > Devices Settings > Under Local Administration Settings, Change the state to NONE for "Registering user is added as local administrator on the device during Microsoft Entra join (Preview)"
upvoted 1 times
...
...
Alboo007_rs007
6 months ago
Selected Answer: D
Correct Answer is D ...
upvoted 1 times
...
Pisces225
6 months ago
Selected Answer: A
Only Autopilot prevents the auto join. The people saying D are referencing how to update the local admin after the fact. Using the method referenced in the link has no effect on the automatic addition of the user joining the device, that has to be done in Autopilot.
upvoted 1 times
...
AleFCI1908
6 months, 3 weeks ago
Selected Answer: D
D - https://learn.microsoft.com/en-us/entra/identity/devices/assign-local-admin#manage-the-microsoft-entra-joined-device-local-administrator-role
upvoted 2 times
...
bigreg
8 months, 2 weeks ago
Selected Answer: D
Identity > Devices > Overview > Device settings
upvoted 1 times
bigreg
8 months, 2 weeks ago
I changed my mind, I thinks its A now. Windows Autopilot - Windows Autopilot provides you with an option to prevent primary user performing the join from becoming a local administrator by creating an Autopilot profile. I hate how this is worded.
upvoted 2 times
FemiA55
5 months, 2 weeks ago
The question is at Entra id join level. Way before Intune & Autopilot. Correct answer is: D
upvoted 1 times
...
Pisces225
6 months ago
Correct. The question asks how to prevent them from ever having been added as a local admin to begin with.
upvoted 1 times
...
...
...
EUC_PRO
8 months, 3 weeks ago
Selected Answer: D
Confired. It is D - https://learn.microsoft.com/en-us/entra/identity/devices/assign-local-admin#manage-the-microsoft-entra-joined-device-local-administrator-role
upvoted 2 times
...
Cezt
10 months ago
Selected Answer: D
You can Join the devices i n many ways not just autopilot D
upvoted 3 times
...
oopspruu
10 months, 1 week ago
Selected Answer: D
Entra Device Settings > Registering user is added as local administrator on the device during Microsoft Entra join (Preview) Technically, A can achieve this too. The question didn't specify if its during OOBE or for Autopilot. So the vagueness makes me incline towards D.
upvoted 2 times
...
chafe
10 months, 3 weeks ago
Selected Answer: D
Checked in tenant and ability to restrict local admin privs to some, all or none is present in device settings as preview. Was added ~March '24, the longer you are reading this from now the more likely it is to be right. I still favour D as the question doesn't mention Autopilot, and if you go the autopilot route everyone's device is getting reset.
upvoted 1 times
...
CJL324
1 year ago
D. Device settings in Azure AD. Device settings in Azure AD allow you to configure policies that control device behavior, including settings related to device enrollment and management. You can use these settings to configure restrictions on local administrator access to devices enrolled in Azure AD.
upvoted 1 times
CJL324
1 year ago
Option A, Windows Autopilot, primarily focuses on simplifying the deployment and management of Windows devices, including Windows 11 devices, through cloud-based services. While Windows Autopilot offers various configuration options for device provisioning and enrollment, it does not directly control the membership of local groups on devices. Configuring Windows Autopilot might not directly address the requirement to prevent users from being added automatically to the local Administrators group on Windows 11 devices joined to the contoso.com Azure AD tenant. Therefore, while Windows Autopilot can play a role in device provisioning and enrollment, it may not be the most appropriate choice for addressing the specific requirement stated in the scenario.
upvoted 1 times
...
...
62b396d
1 year, 1 month ago
Selected Answer: D
Doesn't say anything about autopilot, just that a user joins their device. so D, Device Settings.
upvoted 2 times
...
62b396d
1 year, 1 month ago
doesnt say anything about autopilot. it says "when user joins". wouldn't that be D? If they never go through autopilot, then Autopilot profile won't do anything.
upvoted 1 times
...
ejonesy80
1 year, 1 month ago
Right Answer = A Manage regular users: By default, Microsoft Entra ID adds the user performing the Microsoft Entra join to the administrator group on the device. If you want to prevent regular users from becoming local administrators, you have the following options: Windows Autopilot - Windows Autopilot provides you with an option to prevent primary user performing the join from becoming a local administrator by creating an Autopilot profile. Bulk enrollment - a Microsoft Entra join that is performed in the context of a bulk enrollment happens in the context of an autocreated user. Users signing in after a device has been joined aren't added to the administrators group. Source: https://learn.microsoft.com/en-us/entra/identity/devices/assign-local-admin#manage-regular-users
upvoted 2 times
...
MJFT
1 year, 1 month ago
Selected Answer: D
https://learn.microsoft.com/en-us/entra/identity/devices/howto-manage-local-admin-passwords Enabling Windows LAPS with Microsoft Entra ID
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...