What should you configure to meet the technical requirements for the Azure AD-joined computers?
You need to meet the OOBE requirements for Windows AutoPilot.
Which two settings should you configure from the Azure Active Directory blade? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.

You need to meet the requirements for the MKG department users.
What should you do?
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

You have two Windows 11 devices enrolled in Microsoft Intune as shown in the following table.

The compliance policy settings are configured as shown In the following exhibit.

These settings configure the way the compliance service treats devices. Each device evaluates these as a " Built-in Device Compliance Policy " , which is reflected in device monitoring.

On August1, you create a compliance policy as shown in the following exhibit.


For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

You have a Microsoft 365 E5 subscription that contains a user named User! and a web app named Appl.
App1 must only accept modern authentication requests.
You plan to create a Conditional Access policy named CAPolicy1 that will have the following settings:
• Assignments
° Users or workload identities: User1
° Cloud apps or actions: App1
• Access controls
° Grant: Block access
You need to block only legacy authentication requests to Appl. Which condition should you add to CAPolicy1?
You have a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.

The tenant contains a standalone workgroup computer named Computer1 that runs Window 11. Computer1 contains the local users shown in the following table.

Computer1 needs to be joined to contoso.com.
Which local users can join Computer1 to contoso.com, and the Microsoft Entra credentials of which user can be used? To answer,
select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have the MDM Security Baseline profile shown in the MDM exhibit. (Click the MDM tab.)
You have the ASR Endpoint Security profile shown in the ASR exhibit. (Click the ASR tab.)

You plan to deploy both profiles to devices enrolled in Microsoft Intune. You need to identify how the following settings will be configured on the devices:
• Block Office applications from creating executable content
• Block Win32 API calls from Office macro
Currently, the settings are disabled locally on each device.
What are the effective settings on the devices? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have a Microsoft 365 E5 subscription that uses Microsoft Intune Suite and contains 500 devices that are either hybrid joined or Microsoft Entra joined.
You plan to deploy Endpoint Privilege Management (EPM).
You need to ensure that users can only run apps as an administrator when they meet the following requirements:
• The users are approved by a member of your company ' s IT department.
• The users are signed in to a device that is only Microsoft Entra joined.
The solution must minimize administrative effort.
Which policy should you create, and to what should you assign the policy? To answer, select the appropriate options in the answer

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.
You use Microsoft Intune to manage devices.
You plan to create Windows 11 device builds for the marketing and research departments The solution must meet the following requirements:
• Marketing department devices must support Windows Update for Business.
• Research department devices must have support for feature update versions for up to 36 months from release.
What is the minimum Windows 11 edition required for each department? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point
