exam questions

Exam MD-101 All Questions

View all questions & answers for the MD-101 exam

Exam MD-101 topic 2 question 9 discussion

Actual exam question from Microsoft's MD-101
Question #: 9
Topic #: 2
[All MD-101 Questions]

Your network contains an Active Directory domain. The domain contains 2,000 computers that run Windows 10.
You implement hybrid Microsoft Azure Active Directory (Azure AD) and Microsoft Intune.
You need to automatically register all the existing computers to Azure AD and enroll the computers in Intune. The solution must minimize administrative effort.
What should you use?

  • A. An Autodiscover address record.
  • B. A Windows AutoPilot deployment profile.
  • C. An Autodiscover service connection point (SCP).
  • D. A Group Policy object (GPO).
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Mendel
Highly Voted 5 years, 7 months ago
D should be correct. https://docs.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy
upvoted 35 times
Sortjuh
5 years, 6 months ago
From the url you provided: "Auto-enrollment into Intune via Group Policy is valid only for devices which are hybrid Azure AD joined. This means that the device must be joined into both local Active Directory and Azure Active Directory." The question leads me to believe these devices aren't joined to Azure AD yet, and therefore the group policy wouldn't work. Correct me if I'm wrong.
upvoted 7 times
PESK
5 years, 6 months ago
Answer should be B: You're right. You can use GPO to register devices into Intune, but they must be AzureAD joined as a pre-req.
upvoted 9 times
Nemo19
5 years, 3 months ago
Correct answer is D! In Fact the question says: "You implement hybrid Microsoft Azure Active Directory (Azure AD) and Microsoft Intune."
upvoted 7 times
cantCme
4 years, 8 months ago
"You need to automatically register all the existing computers to Azure AD" So they aren't enrolled just yet.
upvoted 8 times
egdeeptha
3 years, 10 months ago
Yes, This GPO can enroll On premises AD joined devices to Intune Automatically. The answer is D. Requirements: Active Directory-joined PC running Windows 10, version 1709 or later The enterprise has configured a mobile device management (MDM) service The on-premises Active Directory must be integrated with Azure AD (via Azure AD Connect) The device should not already be enrolled in Intune using the classic agents (devices managed using agents will fail enrollment with error 0x80180026) The minimum Windows Server version requirement is based on the Hybrid Azure AD join requirement. See How to plan your hybrid Azure Active Directory join implementation for more information.
upvoted 1 times
...
...
...
RodrigoT
3 years ago
You are right. If you use GPO you can only enroll the devices in MDM, not join them to Azure AD. This question will repeat on Page 1 Question #5 and the answer is always B. Autopilot Deployment Profile. I got this same question in a KAPLAN practice test and the answer is also B.
upvoted 4 times
...
...
CvdK
4 years, 5 months ago
Yes, it will work. From https://docs.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy : The enrollment into Intune is triggered by a group policy created on your local AD and happens without any user interaction. And Starting in Windows 10, version 1607, once the enterprise has registered its AD with Azure AD, a Windows PC that is domain joined is automatically Azure AD–registered.
upvoted 3 times
CvdK
4 years, 5 months ago
So D is the correct answer!
upvoted 9 times
MZONDERL
3 years, 3 months ago
Azure AD–registered is not the same as Azure AD Joined...
upvoted 2 times
Dnyc
2 years, 2 months ago
You cannot be joined to AD and Azure AD at the same time. In hybrid join scenario as stated, you join AD, and register with Azure AD.
upvoted 1 times
...
...
...
...
...
...
jojolabubu
Highly Voted 4 years, 6 months ago
I think B is correct To join the domain to AAD you would use AAD Connect Then you would use a GPO to enroll in Intune But we want to do both at the same time, Autopilot is supposed to do that
upvoted 14 times
mikl
3 years, 4 months ago
Thats not how you minimize administrative effort - answer is D.
upvoted 2 times
...
RodrigoT
3 years ago
The link provided is for using Autopilot to join a device to an on-premises Active Directory domain. The question is exactly the opposite, to join and enroll EXISTING on-premises devices to AzureAD. To achieve this you use Group Policy. End of story. https://docs.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy#configure-the-auto-enrollment-for-a-group-of-devices
upvoted 2 times
RodrigoT
3 years ago
FINAL ANSWER: B is correct. I just got this question on a KAPLAN practice test. You can use an Autopilot Deployment Profile for joining computers to your on-premisses AD domain, and the steps are: 1-Register the device with Windows Autopilot 2-Create an Autopilot deployment profile 3-Specify Hybrid Azure AD as the method 4-Install the Intune Connector for Active Directory on a computer running Windows Server 2016 https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-autopilot-hybrid-azure-ad-join-and-automatic/ba-p/286126
upvoted 5 times
...
...
...
Mkrmn
Most Recent 3 months, 3 weeks ago
Selected Answer: D
In Avanset with a .VCE file the correct answer is D: a Windows Autopilot deployment profile.. In ExamPrepper the correct answer is B: a Group Policy Object (GPO).. I'm confused now, what is the correct answer in the exam?
upvoted 1 times
...
Amir1909
1 year, 3 months ago
D is correct
upvoted 1 times
...
Contactfornitish
1 year, 6 months ago
Selected Answer: D
A. An Autodiscover address record. Not relevant, nowhere mentioned in auto-pilot requirements B. A Windows AutoPilot deployment profile. How you deploy the profile if the device is NOT ENROLLED in Intune yet? C. An Autodiscover service connection point (SCP). Yes! this step is required for case, whenever no AD D. A Group Policy object (GPO). For Hybrid joined device, when enrollment is not done yet, easiest option is GPO since it's managed by AD https://learn.microsoft.com/en-us/windows/client-management/enroll-a-windows-10-device-automatically-using-group-policy
upvoted 1 times
...
lannythewizard
2 years ago
Selected Answer: D
I think D. Crux of this question is with least administrative effort. It mentions devices are joined to Active Directory, so you can use a GPO in this case. If they were Azure AD joined, GPO obviously wouldn't be an option, but since they are you can use a GPO to enroll into MDM automatically
upvoted 1 times
...
zm9
2 years ago
The question mentions that: A hybrid Microsoft Azure Active Directory (Azure AD) and Microsoft Intune are already implemented >> This means devices are already registered in the Azure AD Starting in Windows 10, version 1607, once the enterprise has registered its AD with Azure AD, a Windows PC that is domain joined is automatically Azure AD–registered The second request is to enroll the computers in Intune >> there are two ways (B and D) The third request is to minimize administrative effort >> Answer D is has the less administrative effort
upvoted 2 times
...
Titus42
2 years, 1 month ago
B People need to keep in mind you don't need to touch these 2000 machines individually, your provider can just give you a csv. file with all of the information needed to upload right into the cloud.
upvoted 1 times
...
An1m4_
2 years, 2 months ago
Selected Answer: D
D, GPOs allow to enroll your Hybrid devices in AAD and Intune easily and with minimal effort
upvoted 2 times
...
Meebler
2 years, 4 months ago
B, Option A: An Autodiscover address record, is not relevant in this scenario. Autodiscover is a feature in Microsoft Exchange that allows clients to automatically discover and configure their Exchange server connection settings. It is not related to registering and enrolling devices in Azure AD and Intune. Option C: An Autodiscover service connection point (SCP), is also not relevant in this scenario. An SCP is an Active Directory object that allows clients to locate the Autodiscover service for their domain. It is not related to registering and enrolling devices in Azure AD and Intune. Option D: A Group Policy object (GPO), is also not relevant in this scenario. Group Policy is a feature in Windows that allows you to configure and manage settings and policies for computers and users in a domain. While Group Policy can be used to configure various settings on devices, it is not specifically designed for registering and enrolling devices in Azure AD and Intune. Therefore, the solution that minimizes administrative effort in this scenario is to use a Windows AutoPilot deployment profile.
upvoted 2 times
...
Graz
2 years, 4 months ago
There's the practical real life way to tackle these scenarios and then there is the Microsoft way. With old questions with a ton of debate that the mods don't switch, that typically the answer Microsoft is looking for (even if it is ass backwards).
upvoted 1 times
...
gigiscula
2 years, 4 months ago
Guys, the answer is D. A - I don't even consider it It's said "You implement hybrid Microsoft Azure Active Directory (Azure AD) and Microsoft Intune." So you have configured Azure AD Connect for Hybrid mode and SCP it's automatically created on Active Directory. So C it's out. B - If completely resetting 2000 machines is considered a minimum effort I challenge anyone to propose it to a customer. Also, Windows Autopilot only works the first time you start your PC. Only D remains, which is in any case the only viable and correct solution
upvoted 1 times
...
DDHP7
2 years, 5 months ago
the key words is " hybrid Microsoft Azure Active Directory " which mean it has AD and AAD, therefore, auto-enroll AD PCs to Intune would be D use GPO, which I have done in my last job
upvoted 2 times
...
Deric
2 years, 8 months ago
Lots of opinions here, but after doing some research I found this link, which as I understand it, points to B as the solution: https://docs.microsoft.com/en-us/mem/intune/configuration/domain-join-configure?source=recommendations
upvoted 1 times
...
raduM
2 years, 9 months ago
B shopuld be correct
upvoted 1 times
...
Harold
2 years, 12 months ago
Selected Answer: B
In the official MCA MD101 practice tests from Wiley, the answer to this question is B - Windows Autopilot. I tend to agree with it, because it's not stated whether the existing devices are already even hybrid-joined, only that they want to. So yes, I'd say it's B.
upvoted 2 times
...
MR_Eliot
3 years ago
Selected Answer: C
C. You need to configure SCP records. You can do this by using Azure Connect tool.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago