exam questions

Exam MS-101 All Questions

View all questions & answers for the MS-101 exam

Exam MS-101 topic 1 question 9 discussion

Actual exam question from Microsoft's MS-101
Question #: 9
Topic #: 1
[All MS-101 Questions]

You have Windows 10 Pro devices that are joined to an Active Directory domain.
You plan to create a Microsoft 365 tenant and to upgrade the devices to Windows 10 Enterprise.
You are evaluating whether to deploy Windows Hello for Business.
What are two prerequisites of the deployment? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

  • A. Microsoft Endpoint Manager enrollment
  • B. Microsoft Azure Active Directory (Azure AD)
  • C. smartcards
  • D. TPM-enabled devices
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
marckinez
Highly Voted 4 years, 2 months ago
it's correct
upvoted 17 times
...
[Removed]
Highly Voted 3 years, 8 months ago
The answer is A and B, there is the ref. https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-identity-verification
upvoted 9 times
OomensRob
3 years, 8 months ago
For all who claim TPM is pre-requisite for WH4B: TPM is ONLY used for biometric recognition in conjunction with WH4B. WH4B can be used with just a pin code as well and thus no TPM is required for WH4B
upvoted 11 times
...
...
RahulX
Most Recent 1 year, 11 months ago
Correct answer is A & B
upvoted 1 times
...
PL1313
2 years, 2 months ago
Answer is A and D. TPM Enabled Devices are now a requirement for Windows Enterprise: Since July 28, 2016, all new device models, lines, or series (or if you're updating the hardware configuration of an existing model, line, or series with a major update, such as CPU, graphic cards) must implement and enable by default TPM 2.0 (details in section 3.7 of the Minimum hardware requirements page). The requirement to enable TPM 2.0 only applies to the manufacturing of new devices. For TPM recommendations for specific Windows features, see TPM and Windows Features.
upvoted 1 times
ann0ysum0
2 years, 2 months ago
The scope of the question is evaluating WH4B deployment. For that, TPM isn't required. Though the devices will have to have it for Win10 Ent upgrade, they don't need it for WH4B. Given answer (A&B) is correct.
upvoted 2 times
...
...
TechMinerUK
2 years, 8 months ago
The question seems to be incorrectly worded as from my understanding none of the listed answers are requirements for WHFB. Whilst in a hybrid deployment you would need AzureAD (In order for it to be hybrid) you wouldn't ever "Require" TPM, Smartcards or Intune despite it being possible to use all of them in the deployment of WHFB. "Required" would make me assume that it is mandatory regardless of the setup e.g. it is required you need a computer
upvoted 2 times
...
ARYMBS
2 years, 9 months ago
Selected Answer: AB
At first I also answered incorrectly. Problem lies with the question itself... IGNORE the sentence "You are evaluating whether to deploy Windows Hello for Business" because none of the four answers are the WHfB requirements.... Pay attention only to "You plan to create a Microsoft 365 tenant and to upgrade the devices to Windows 10 Enterprise.". If we apply this logic: B - because you plan to create Microsoft 365 tenant. A - because you plan to upgrade the devices to Windows 10 Enterprise (I think it is a modern way to upgrade Pro to Enterprise without sign out). SO the answers are correct? I'm really sad about this kind of questions from Microsoft :(
upvoted 7 times
...
AVR31
2 years, 11 months ago
Selected Answer: AB
From the answers provided, TPM and smart cards are definitely NOT required. Intune isn't either, but it given as optional in the official documentation, so choosing that: https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-identity-verification
upvoted 3 times
...
Krish1610
2 years, 11 months ago
Selected Answer: AB
Correct answer is A & B
upvoted 3 times
...
Contactfornitish
3 years ago
Selected Answer: AB
Windows Hello for Business definitely possible without TPM or Smart card https://docs.microsoft.com/en-us/windows/security/information-protection/tpm/tpm-recommendations
upvoted 3 times
...
Alv86
3 years ago
Selected Answer: AD
I have set it up and we do not have intune, only ad connect and tpm for devices.
upvoted 2 times
...
Zardu
3 years, 3 months ago
Required: Windows 10, version 1511 or later, or Windows 11 Microsoft Azure Account Azure Active Directory Azure AD Multifactor Authentication Optinoal: Modern Management (Intune or supported third-party MDM), optional Azure AD Premium subscription - optional, needed for automatic MDM enrollment when the device joins Azure Active Directory (from link provided by AniIT)
upvoted 3 times
...
PDR
3 years, 5 months ago
TPM definitely not required - I use WHFB on my desktop that does not have TPM and I login with a fingerprint reader (or pin). I think A and B is the correct answer because to enable Windows Hello for Business (N.B. not just Windows Hello which can be used on a standalone machine) you need to do this through intune. A user would have to have an account in an AAD tenant also
upvoted 4 times
...
gxsh
3 years, 6 months ago
Answer is correct.
upvoted 3 times
...
UWSFish
3 years, 9 months ago
According to the literature neither TPM nor Intune is actually required. However I believe TPM is the better answer. However between the two TPM seems the better answer. The whole point is to use PIN/biometric as a mechanism to load the private key. While this key can be stored on the file system, the whole idea is for it to be stored on TPM. So I think AAD & TPM is correct.
upvoted 2 times
...
Patrick2401
3 years, 9 months ago
I think the right answer is AAD/TPM. Microsoft state: Modern Management (Intune or supported third-party MDM), optional It's optional not a requirement. The device has to be AAD-joined. Smart cards solution has nothing to do with this. So the only option left is TPM.
upvoted 1 times
...
JhonyTrujillo
3 years, 10 months ago
A Trusted Platform Module (TPM) provides an additional layer of data security. If set to required, only devices with an accessible TPM can provision Windows Hello for Business. If set to preferred, devices attempt to use a TPM, but if not available will provision using software.
upvoted 1 times
...
afbnfz
4 years ago
A and B. TPM is NOT a prerequisite for Hello for Business. https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-identity-verification
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...