C06.Planning and Managing Microsoft Intune Flashcards
- You are the network administrator for your organization. Your users use both desktops and tablets to access the network. Your tablet users use a 4G mobile broadband Wi-Fi connection. You need to watch how much data your users are using on this connection. How do you do that?
A. Configure the broadband connection as a metered network.
B. Turn on network resource monitoring.
C. Enable performance monitor.
D. Enable tablet metering in the tablets settings.
A. Configure the broadband connection as a metered network.
- A. Administrators have the ability to limit and monitor network usage by configuring the network as a metered network. Network metering allows network downloading to be watched or metered, and then administrators can charge users or departments for the network usage.
- You are the network administrator for a company that has a Microsoft Intune subscription. You have decided to set up three Intune Security groups called CorpGroup, NHGroup, and Portsmouth. CorpGroup is a parent group to Portsmouth. Portsmouth has 75 users in the group. You realized that you need to make NHGroup the parent to Portsmouth. What is the first thing that you need to do?
A. Edit the security properties of CorpGroup.
B. Edit the security properties of NHGroup.
C. Remove all 75 users from Portsmouth
D. Delete Portsmouth and then re-create the Portsmouth group under NHGroup.
D. Delete Portsmouth and then re-create the Portsmouth group under NHGroup.
- D. Microsoft Intune does not allow you to change a security group parent. When you delete a group, the users are not deleted, and the only way to change a group’s parent group is to create the security group under the parent. So, Portsmouth needs to be re-created under NHGroup, and then the users need to be re-added to Portsmouth.
- You are the IT manager of a large manufacturing company. Sales personnel are allowed to bring their own personal Windows 10 devices to the office. The company allows the sales people to install company software and use their devices to retrieve company mail by using the management infrastructure agent. One of your salespeople reports that their Windows 10 laptop was stolen while at the airport. You need to make sure that no one can steal any of the corporate data or access any corporate emails. Which two actions should you perform? Each correct answer presents part of the solution.
A. Prevent the computer from connecting to the corporate wireless network.
B. Remove the computer from the management infrastructure.
C. Reset the user’s password.
D. Do a remote wipe on the users laptop.
C. Reset the user’s password.
D. Do a remote wipe on the users laptop.
- C, D. As long as the salesperson’s personally owned Windows 10 laptop is being managed by the management infrastructure agent, administrators can use remote wipe feature. When you do a remote wipe, all of the company’s data gets wiped from the device.
- You are the IT director for a large school system. The school has decided that students can bring in their own devices to do school work with. Your organization uses Microsoft Azure Active Directory and Intune for all of the student’s applications and network authentication.
You need to be sure that students that are using IPADs as well as Windows 10 devices have full access. What do you need to do to be sure that all iOS devices can get access?
A. Add a Student Portal app from the Apple App Store.
B. Create a device enrollment manager account.
C. Configure an Intune Service Connector for Exchange.
D. Import an Apple Push Notification service (APNs) certificate.
D. Import an Apple Push Notification service (APNs) certificate.
- D. An Apple Push Notification service (APNs) certificate must be imported from Apple so that the school can manage iOS devices. This certificate allows Intune administrators to manage iOS.
- You are the administrator for Stormwind Studios. Stormwind has subscribed to Microsoft Intune. All of your client computers are running Windows 10 Enterprise. Users are complaining that they get prompted to restart their systems after mandatory updates. You need to stop the prompts from appearing on the clients Windows 10 systems following their updates. Which Intune policy template should you use?
A. Microsoft Intune Agent Settings.
B. Windows Intune Policy Configuration.
C. Microsoft Intune Security Settings.
D. You need to create a Custom Windows 10 Policy.
A. Microsoft Intune Agent Settings.
- A. To configure the update restart prompt setting, you must configure the Microsoft Intune Agent Settings policy. Setting the “Prompt user to restart Windows during Intune client agent mandatory updates” to No, this would stop users from receiving restart prompts after mandatory updates.
- You are the IT Manager for WillPanek.com. The company has an Active Directory and a cloud-based Azure Active Directory. The two are synchronized by using the Azure Active Directory Synchronization Tool. The company also uses System Center Configuration Manager. You need to use Configuration Manager to manage devices registered with Intune. What do you need to do to accomplish this? (Choose two.)
A. Create a new device enrollment manager account in Microsoft Intune.
B. In Microsoft Intune, configure an Active Directory Connector.
C. Configure the Microsoft Intune Connector role in Configuration Manager.
D. Create the Microsoft Intune subscription in Configuration Manager.
C. Configure the Microsoft Intune Connector role in Configuration Manager.
D. Create the Microsoft Intune subscription in Configuration Manager.
- C, D. If using Configuration Manger, administrators must configure Configuration Manager to manage mobile devices. To do this, it requires administrators to create a Windows Intune subscription and use a connector to synchronize user accounts.
- You are the administrator of your organization’s Active Directory domain. The owners of the company want to move to the cloud by using Azure Active Directory. You need to be able to have the on-site version of Active Directory work with the cloud-based Azure Active Directory. What do you need to install to make this happen?
A. The Active Directory (AD) user connector
B. Azure Active Directory (AD) Connect tool
C. Microsoft Intune Connection tool
D. Microsoft Intune single sign-on tool
B. Azure Active Directory (AD) Connect tool
- B. Administrators can have the cloud-based version of Active Directory (Azure Active Directory) work with the on-premise server-based version of Active Directory by using the Azure Active Directory (AD) Connect tool (formerly known as the Directory Synchronization tool, the Directory Sync tool, or the DirSync.exe tool).
- You are the IT director for large company that has decided to move to the cloud. The company wants to use Azure Active Directory and Microsoft Intune. The company has been looking into this because users have been using multiple devices to get their job done. When your users get added to Intune and get licensed, how many devices can each user add by default?
A. 3
B. 4
C. 5
D. None. Device Administrators are the only person who can add devices to Intune.
C. 5
- C. By default, licensed users can add up to five devices to their accounts. Device Administrators have the ability to add devices to Intune, but users do have the ability to enroll five devices on their own.
- You are the administrator of a company that builds its own applications. You have decided that you want to install a company application to all employees by using the Windows Store. Which term is used to refer to installing corporate apps through the Windows Store?
A. WS Installations
B. BranchCache
C. Image installation
D. Sideloading
D. Sideloading
- D. Sideloading an application means that you are loading an application that you already own or one that your company created into a delivery system (i.e., Intune, Microsoft Store, or images).
- You are the IT Director for Stormwind training studios. Your company has decided to start using Microsoft Intune for all of their software deployments. You want to set up a notification system so that you see all alerts and that you IT Manager only gets notified for Critical alerts. How do you accomplish this? (Choose all that apply.)
A. Set up all event notifications for the IT Manager in Intune.
B. Set up all event notifications for the IT Director in Intune.
C. Set up Critical event notifications for the IT Manager in Intune.
D. Set up Critical event notifications for the IT Manager in Intune.
B. Set up all event notifications for the IT Director in Intune.
C. Set up Critical event notifications for the IT Manager in Intune.
- B, C. Intune administrators have the ability to set up different notifications to different emails based on alert type. So, you can send all alerts, critical alerts, warnings, and informational alerts to different IT members.