Enroll devices using Intune Flashcards

1
Q

What are the four stages of the MDM lifecycle?

A

Enrol, Configure, Protect, Retire

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What must be configured in the ‘Device Enrolment’ section of Intune before devices can enroll?

A

The MDM authority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which device types is Intune configured to allow by default?

A

Windows, Android, and standard Samsung Knox devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What do iOS and MacOS devices require to be set up in Intune before enrolment can occur?

A

Apple MDM Push Certificate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does CSR stand for and what does it do?

A

Certificate Signing Request

File downloaded from Intune and uploaded to the Apple Certificate Portal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What requirements must a user meet in order to generate a certificate file in the Apple Certificate Portal?

A

An Apple ID that is a member of the Apple Developer Program

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

For Windows devices already joined to on-prem AD-DS, how can you automatically enroll them in MDM?

A

Using Group Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the manual methods of enrolling Windows devices in MDM?

A

-Settings app
-Provisioning Packages
-Company Portal app

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

True or false: automatic enrolment in MDM only works for Windows devices

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Why does automatic enrolment in MDM only work for Windows devices?

A

Only Windows devices can be joined to on-prem AD-DS or Entra ID.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is automatic enrolment for Windows devices?

A

Devices automatically enrol in MDM when they join or register with Entra ID

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What Entra ID license is required for automatic MDM enrollment

A

Entra ID P1/P2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does WIP stand for?

A

Windows Information Protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

True or false: MFA is enabled for automatic enrolment by default

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the earliest Android version Intune supports for device enrolment?

A

8.0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the earliest iOS version Intune supports for device enrolment?

A

14.0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is the earliest MacOS version Intune supports through device enrolment?

A

11.0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

True or false: all users with an Intune license are allowed to enrol supported devices by default

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What Enrolment Restrictions can be configured to allow/deny enrolment for certain devices?

A

-Maximum number of enrolled devices for a user
-Device platform
-Required OS version
-Restrict enrolment of personally owned devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is the default maximum number of enrolled devices for a user?

A

5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What are the supported Corporate Identifiers you can upload to specify company-owned devices?

A

Serial number & IMEI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What action would you take in Intune to only allow enrolled devices to access company resources?

A

Conditional access policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is the difference between a Compliance Policy and a Conditional Access Policy?

A

Compliance Policy - defines the configuration required to be considered compliant

Conditional Access Policy - controls access to company resources (can be based on Compliance Policies).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What Group Policy would you use to MDM-enrol devices joined to an on-prem AD-DS which is synced to Entra?

A

‘Enable automatic MDM enrolment using default Entra credentials’

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Why is it recommended not to use the .onmicrosoft.com domain?
Using a custom domain lets users sign in with the credentials they use to access other domain resources.
26
Where in the Intune portal can you configure Automatic enrolment?
Devices -> Enroll Devices -> Automatic enrollment
27
What enrolment method can be used if you don't have Entra ID P1/P2?
CNAME enrolment
28
What is the Intune MDM server address?
enrollment.manage.microsoft.com
29
What are the 8 methods of Windows enrolment?
-Add Work or School account -Enrol only in device management -Entra join (OOBE) -Entra join (Autopilot - user-driven deployment mode) -Entra join (Autopilot - self-deploying mode) -Enrol in MDM only (DEM user) -Configuration Manager co-management -Entra join (bulk enrollment)
30
True or false: The 'Enrol only in device management' Windows enrolment method enrolls the device in Intune and joins it to Entra
False - it only enrols in Intune and does not Entra-join the device
31
When would the 'Enrol only in device management' Windows enrolment method be used?
When the environment doesn't have the P1/P2 Entra ID licenses required for auto-enrollment
32
What is the preferred Windows enrollment method?
-Entra join (Autopilot - user-driven deployment mode)
33
What is the difference between the Autopilot user-driven & self-deploying modes?
Self-deploying skips all OOBE screens and requires minimal user interaction, most commonly used for Kiosks.
34
What is the maximum number of devices that can be enrolled by a DEM?
1000
35
What is the process of the 'Enroll in MDM only' Windows enrolment method?
A DEM enrolls the device and installs apps before handing to the user
36
What is the preferred way to enroll pre-existing Windows devices already in Configuration Manager?
Co-management
37
How does the Entra Join(Bulk enrollment) Windows enrollment method work?
Users are provided a Provisioning Package which automatically enrolls devices.
38
How can a user with an Intune license enrol an Android device?
Download the Intune Company Portal app through Google Play
39
What does the Android Enterprise Work Profile achieve?
Separation of work and personal information on an Android device. Deploys apps & configuration to only the work profile.
40
What is Android Enterprise Dedicated?
Single function devices locked down to specific apps
41
What is Android Enterprise Fully Managed?
Corporate owned, single function devices used exclusively for work
42
What is a prerequisite to setting up Android Enterprise?
Link your Intune tenant account to your managed Google Play account and set up an enrollment profile
43
How can a user enrol an iOS device?
Download the Intune Company Portal app through the Apple App Store
44
What enrollment methods does Intune support for company-owned iOS devices?
-ABM -ADE -Apple School Manager -Apple Configurator -Intune DEM account -Device Enrollment Program
45
What does ADE stand for?
Automated Device Enrollment
46
How does Apple DEP work?
Companies purchase iOS devices directly and can configure settings or Intune enrollment from the DEP portal
47
What device information is needed to assign Apple devices to Intune for management?
A list of serials or a Purchase Order number
48
True or False: iOS devices enrolled in DEP still need to download the Company Portal app
False
49
What is iOS Supervised Mode for?
Corporate owned devices - provides more controls.
50
From what version of iOS onwards is Supervised Mode mandatory for DEP configured devices?
11.0
51
When is a DEM account most useful?
When devices are enrolled and prepared before distribution to users
52
If a user requires individual configuration such as an email profile, should a DEM enroll the device?
No - users should enroll it themselves
53
True or False: A DEM shouldn't be an admin for security reasons
True
54
With what Apple features can a DEM account NOT be used?
-Apple Configurator with Setup Assistant -Apple Configurator with Direct Enrollment -Apple School Manager -Device Enrollment Program
55
What does DEP stand for?
Device Enrollment Program
56
What does ASM stand for?
Apple School Manager
57
What is the maximum number of devices a DEM can enroll?
1000
58
What are the limitations on a device enrolled by a DEM?
-No per-user access (no assigned user) -The DEM user can't unenroll DEM-enrolled devices on the device itself (only an Intune admin can unenroll) -Users can't use VPP apps with user licenses because of per-user Apple ID requirements for app management -You can't use Apple Configurator/ASM/DEP to enroll devices, so no Supervised Mode
59
What is the maximum number of Android Work Profile devices a DEM can enroll?
10
60
What does Apple VPP stand for and what does it do?
Apple Volume Purchase Program A service that allows organizations or educational institutions to purchase corporate apps in bulk, and silently deploy and manage them on devices.
61
What deprecated services does Apple Business Manager combine?
VPP & DEP
62
Where in Intune can you find reports about device status?
Devices -> Monitor
63
What does the Retire device action do?
Removes company data and removes the device from Intune management.
64
Which device types support the Remote Lock action?
Android, iOS, MacOS
65
Which device types support the Reset Passcode action?
Android and iOS
66
What does the Fresh Start device action do?
Windows only - removes all apps, including preinstalled OEM apps
67
What does the Autopilot Reset device action do?
Windows only - initiates the device reset process but retains Entra ID and Intune connection, WiFi details, provisioning packages, and SCEP certificates
68
Which device types support the Locate Device action?
Windows, iOS, Android Enterprise Dedicated