exam questions

Exam MD-101 All Questions

View all questions & answers for the MD-101 exam

Exam MD-101 topic 4 question 32 discussion

Actual exam question from Microsoft's MD-101
Question #: 32
Topic #: 4
[All MD-101 Questions]

Your company has a Microsoft 365 subscription.
A new user named Admin1 is responsible for deploying Windows 10 to computers and joining the computers to Microsoft Azure Active Directory (Azure AD).
Admin1 successfully joins computers to Azure AD.
Several days later, Admin1 receives the following error message: `This user is not authorized to enroll. You can try to do this again or contact your system administrator with the error code (0x801c0003).`
You need to ensure that Admin1 can join computers to Azure AD and follow the principle of least privilege.
What should you do?

  • A. Assign the Global administrator role to Admin1.
  • B. Modify the Device settings in Azure AD.
  • C. Assign the Cloud device administrator role to Admin1.
  • D. Modify the User settings in Azure AD.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
If you have rights to manage devices in Intune, you can manage devices for which mobile device management is listed as Microsoft Intune. If the device isn't enrolled with Microsoft Intune, the Manage option won't be available.
Note: Enable or disable an Azure AD device
There are two ways to enable or disable devices:
The toolbar on the All devices page, after you select one or more devices.
The toolbar, after you drill down for a specific device.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/devices/device-management-azure-portal

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
rbrink2001
Highly Voted 3 years, 11 months ago
Seeing this: This user is not allowed to enroll. Error 0x801c0003: "This user is not allowed to enroll. You can try again or contact your system administrator with the error code 801c0003." Cause: The Users may join devices to Azure AD setting is set to None. It prevents new users from joining their devices to Azure AD. Therefore Intune enrollment fails. Resolution Sign in to the Azure portal as administrator. Go to Azure Active Directory > Devices > Device Settings. Set Users may join devices to Azure AD to All. Enroll the device again. leads me to believe that the answer is B https://docs.microsoft.com/en-us/troubleshoot/mem/intune/troubleshoot-windows-enrollment-errors
upvoted 14 times
tf444
3 years, 7 months ago
It says Admin1 joins the computer to Azure AD, a couple of days later he/she receives the error message. It has to do with the number of devices Admin1 can enroll.
upvoted 9 times
...
...
Pleebb
Highly Voted 3 years, 10 months ago
Modify the Device settings in Azure AD. Maximum number of devices - This setting enables you to select the maximum number of Azure AD joined or Azure AD registered devices that a user can have in Azure AD. If a user reaches this quota, they are not be able to add additional devices until one or more of the existing devices are removed. The default value is 50. You can increase the value up to 100 and if you enter a value above 100, Azure AD will set it to 100. You can also use Unlimited value to enforce no limit other than existing quota limits. https://docs.microsoft.com/en-us/azure/active-directory/devices/device-management-azure-portal
upvoted 12 times
...
ExamTopics1_EIS
Most Recent 2 years, 1 month ago
Selected Answer: B
None are correct today - answer presented before was correct. Modern current answer: Device enrollment managers added from Intune - Device Enrollment > Enroll Device > Device enrollment managers Users added here can enroll 1000 computers.
upvoted 1 times
...
MR_Eliot
3 years ago
B seems correct to me. Assuming the administrator is the one who is enrolling devices to azure we can put him in a group and assign that group in Azure > Device Settings.
upvoted 2 times
...
chapinoli
3 years, 3 months ago
The cause The person receives the error, because he or she has reached the limit of maximum allowed devices to Azure AD Join. By default, Azure Active Directory enforces a limit of 20 devices for any user object to join. It even enforces this limit on privileged users, like users with the Global Admin role (Admin1) https://dirteam.com/sander/2018/03/20/knowledgebase-you-receive-error-801c0003-when-you-try-to-azure-ad-join-a-device-during-the-out-of-the-box-experience-oobe/
upvoted 1 times
...
Goofer
3 years, 6 months ago
increase the device enrollment limit under devices enrollment restriction
upvoted 3 times
...
tf444
3 years, 7 months ago
https://systemcenterdudes.com/intune-error-0x801c003-this-user-is-not-authorized-to-enroll/
upvoted 3 times
...
AdamMSConfig
3 years, 10 months ago
https://docs.microsoft.com/en-us/troubleshoot/mem/intune/troubleshoot-windows-enrollment-errors
upvoted 1 times
...
Perycles
3 years, 11 months ago
B is correct, it's possible to increase the number here : Maximum number of device per user. and it can be also done under intune ( under Enrollement restriction > Device limit restriction)
upvoted 4 times
...
NetY2K
3 years, 11 months ago
The given answer I correct. I checked it myself. In AAD you go to Devices>Device settings> Maximum number of devices per user and choose the number you want to set.
upvoted 3 times
...
JeremyBearimy7
3 years, 11 months ago
I don't think the options you are given are very useful if you want to apply the principle of least privilige. Microsoft gives the solution to increase the device limit in Endpoint through Devices > Enrollment restrictions > Default (under Device limit restrictions) > Properties > Edit (next to Device limit) > increase the Device limit (maximum 15)> Review + Save. Source: https://docs.microsoft.com/en-us/troubleshoot/mem/intune/troubleshoot-windows-enrollment-errors The only problem is that it gives all users the same limit to register devices. Wouldn't a device enrollment manager account be the better option (so modify the user)?
upvoted 4 times
...
Merma
4 years ago
Wouldn't C. Assign the Cloud device administrator role to Admin1. be the correct answer?
upvoted 1 times
bertik
3 years, 11 months ago
No. Cloud device administrator doesn't have permissions to create devices, only enable, disable and delete. https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#cloud-device-administrator So I think answer should be D as Layer8 stated.
upvoted 2 times
...
...
Layer8
4 years ago
the question led me to believe that the user had maxed out their total # of enrollments (15). isn't the goal to modify the user so they can continue to enroll?
upvoted 4 times
Layer8
4 years ago
I suppose the suggested answer would work, but that would allow for all users to add more than the default number of devices.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago