Enroll devices using Intune Flashcards

1
Q

What are the four stages of the MDM lifecycle?

A

Enrol, Configure, Protect, Retire

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What must be configured in the ‘Device Enrolment’ section of Intune before devices can enroll?

A

The MDM authority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which device types is Intune configured to allow by default?

A

Windows, Android, and standard Samsung Knox devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What do iOS and MacOS devices require to be set up in Intune before enrolment can occur?

A

Apple MDM Push Certificate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does CSR stand for and what does it do?

A

Certificate Signing Request

File downloaded from Intune and uploaded to the Apple Certificate Portal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What requirements must a user meet in order to generate a certificate file in the Apple Certificate Portal?

A

An Apple ID that is a member of the Apple Developer Program

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

For Windows devices already joined to on-prem AD-DS, how can you automatically enroll them in MDM?

A

Using Group Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the manual methods of enrolling Windows devices in MDM?

A

-Settings app
-Provisioning Packages
-Company Portal app

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

True or false: automatic enrolment in MDM only works for Windows devices

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Why does automatic enrolment in MDM only work for Windows devices?

A

Only Windows devices can be joined to on-prem AD-DS or Entra ID.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is automatic enrolment for Windows devices?

A

Devices automatically enrol in MDM when they join or register with Entra ID

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What Entra ID license is required for automatic MDM enrollment

A

Entra ID P1/P2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does WIP stand for?

A

Windows Information Protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

True or false: MFA is enabled for automatic enrolment by default

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the earliest Android version Intune supports for device enrolment?

A

8.0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the earliest iOS version Intune supports for device enrolment?

A

14.0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is the earliest MacOS version Intune supports through device enrolment?

A

11.0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

True or false: all users with an Intune license are allowed to enrol supported devices by default

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What Enrolment Restrictions can be configured to allow/deny enrolment for certain devices?

A

-Maximum number of enrolled devices for a user
-Device platform
-Required OS version
-Restrict enrolment of personally owned devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is the default maximum number of enrolled devices for a user?

A

5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What are the supported Corporate Identifiers you can upload to specify company-owned devices?

A

Serial number & IMEI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What action would you take in Intune to only allow enrolled devices to access company resources?

A

Conditional access policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is the difference between a Compliance Policy and a Conditional Access Policy?

A

Compliance Policy - defines the configuration required to be considered compliant

Conditional Access Policy - controls access to company resources (can be based on Compliance Policies).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What Group Policy would you use to MDM-enrol devices joined to an on-prem AD-DS which is synced to Entra?

A

‘Enable automatic MDM enrolment using default Entra credentials’

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Why is it recommended not to use the .onmicrosoft.com domain?

A

Using a custom domain lets users sign in with the credentials they use to access other domain resources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Where in the Intune portal can you configure Automatic enrolment?

A

Devices -> Enroll Devices -> Automatic enrollment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What enrolment method can be used if you don’t have Entra ID P1/P2?

A

CNAME enrolment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What is the Intune MDM server address?

A

enrollment.manage.microsoft.com

29
Q

What are the 8 methods of Windows enrolment?

A

-Add Work or School account
-Enrol only in device management
-Entra join (OOBE)
-Entra join (Autopilot - user-driven deployment mode)
-Entra join (Autopilot - self-deploying mode)
-Enrol in MDM only (DEM user)
-Configuration Manager co-management
-Entra join (bulk enrollment)

30
Q

True or false: The ‘Enrol only in device management’ Windows enrolment method enrolls the device in Intune and joins it to Entra

A

False - it only enrols in Intune and does not Entra-join the device

31
Q

When would the ‘Enrol only in device management’ Windows enrolment method be used?

A

When the environment doesn’t have the P1/P2 Entra ID licenses required for auto-enrollment

32
Q

What is the preferred Windows enrollment method?

A

-Entra join (Autopilot - user-driven deployment mode)

33
Q

What is the difference between the Autopilot user-driven & self-deploying modes?

A

Self-deploying skips all OOBE screens and requires minimal user interaction, most commonly used for Kiosks.

34
Q

What is the maximum number of devices that can be enrolled by a DEM?

A

1000

35
Q

What is the process of the ‘Enroll in MDM only’ Windows enrolment method?

A

A DEM enrolls the device and installs apps before handing to the user

36
Q

What is the preferred way to enroll pre-existing Windows devices already in Configuration Manager?

A

Co-management

37
Q

How does the Entra Join(Bulk enrollment) Windows enrollment method work?

A

Users are provided a Provisioning Package which automatically enrolls devices.

38
Q

How can a user with an Intune license enrol an Android device?

A

Download the Intune Company Portal app through Google Play

39
Q

What does the Android Enterprise Work Profile achieve?

A

Separation of work and personal information on an Android device. Deploys apps & configuration to only the work profile.

40
Q

What is Android Enterprise Dedicated?

A

Single function devices locked down to specific apps

41
Q

What is Android Enterprise Fully Managed?

A

Corporate owned, single function devices used exclusively for work

42
Q

What is a prerequisite to setting up Android Enterprise?

A

Link your Intune tenant account to your managed Google Play account and set up an enrollment profile

43
Q

How can a user enrol an iOS device?

A

Download the Intune Company Portal app through the Apple App Store

44
Q

What enrollment methods does Intune support for company-owned iOS devices?

A

-ABM
-ADE
-Apple School Manager
-Apple Configurator
-Intune DEM account
-Device Enrollment Program

45
Q

What does ADE stand for?

A

Automated Device Enrollment

46
Q

How does Apple DEP work?

A

Companies purchase iOS devices directly and can configure settings or Intune enrollment from the DEP portal

47
Q

What device information is needed to assign Apple devices to Intune for management?

A

A list of serials or a Purchase Order number

48
Q

True or False: iOS devices enrolled in DEP still need to download the Company Portal app

A

False

49
Q

What is iOS Supervised Mode for?

A

Corporate owned devices - provides more controls.

50
Q

From what version of iOS onwards is Supervised Mode mandatory for DEP configured devices?

A

11.0

51
Q

When is a DEM account most useful?

A

When devices are enrolled and prepared before distribution to users

52
Q

If a user requires individual configuration such as an email profile, should a DEM enroll the device?

A

No - users should enroll it themselves

53
Q

True or False: A DEM shouldn’t be an admin for security reasons

A

True

54
Q

With what Apple features can a DEM account NOT be used?

A

-Apple Configurator with Setup Assistant
-Apple Configurator with Direct Enrollment
-Apple School Manager
-Device Enrollment Program

55
Q

What does DEP stand for?

A

Device Enrollment Program

56
Q

What does ASM stand for?

A

Apple School Manager

57
Q

What is the maximum number of devices a DEM can enroll?

A

1000

58
Q

What are the limitations on a device enrolled by a DEM?

A

-No per-user access (no assigned user)
-The DEM user can’t unenroll DEM-enrolled devices on the device itself (only an Intune admin can unenroll)
-Users can’t use VPP apps with user licenses because of per-user Apple ID requirements for app management
-You can’t use Apple Configurator/ASM/DEP to enroll devices, so no Supervised Mode

59
Q

What is the maximum number of Android Work Profile devices a DEM can enroll?

A

10

60
Q

What does Apple VPP stand for and what does it do?

A

Apple Volume Purchase Program

A service that allows organizations or educational institutions to purchase corporate apps in bulk, and silently deploy and manage them on devices.

61
Q

What deprecated services does Apple Business Manager combine?

A

VPP & DEP

62
Q

Where in Intune can you find reports about device status?

A

Devices -> Monitor

63
Q

What does the Retire device action do?

A

Removes company data and removes the device from Intune management.

64
Q

Which device types support the Remote Lock action?

A

Android, iOS, MacOS

65
Q

Which device types support the Reset Passcode action?

A

Android and iOS

66
Q

What does the Fresh Start device action do?

A

Windows only - removes all apps, including preinstalled OEM apps

67
Q

What does the Autopilot Reset device action do?

A

Windows only - initiates the device reset process but retains Entra ID and Intune connection, WiFi details, provisioning packages, and SCEP certificates

68
Q

Which device types support the Locate Device action?

A

Windows, iOS, Android Enterprise Dedicated