Enroll devices using Microsoft Intune - Explain considerations for device enrollment Flashcards

1
Q

What is the preferred method for managing a Windows device ?

A

Enroll it as a mobile device with Intune

Because Windows device has built-in mobile device management features

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What method must be used for enrolling devices running any operating system other than Windows?

A

Device enrollment

This includes devices like phones or Macs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How can Windows devices already joined to on-premises AD DS be enrolled to MDM?

A

Use Group Policy to automatically enroll them

This method simplifies the enrollment process for existing AD DS joined devices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What integration can be configured to automatically enroll Windows devices to MDM?

A

Integration between Microsoft Entra ID and MDM

Joining a device to Microsoft Entra ID triggers automatic MDM enrollment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

List the methods for manually enrolling Windows devices to MDM.

A
  • Using a Settings app
  • Using provisioning packages
  • Using the Company Portal app

Each method allows for flexibility in device management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

True or False: Only Windows devices can be joined to an on-premises AD DS and Microsoft Entra ID.

A

True

This is why automatic enrollment is exclusive to Windows devices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How can Android and iOS devices be enrolled to MDM?

A

Only manually using the Company Portal app

The Company Portal app must be downloaded from app stores.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What must be ensured for enrolling iOS devices to MDM?

A

MDM must be configured with a valid Apple Push Notification (APN) certificate

APN certificates are crucial for secure communication.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which devices require an APN certificate for secure communication with MDM?

A
  • iPhones
  • iPads
  • macOS devices

This requirement applies regardless of the MDM product used.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

11

What kind of devices Intune supports through device enrollment?

A
  • Windows 10/11 (Home, Pro, Education, S mode, and Enterprise versions)
  • Windows 10/11 Cloud PCs on Windows 365
  • Windows 10 IoT and Windows 10 Holographic
  • Windows 10 2019 LTSC
  • Surface Hub
  • Windows 10 Teams (Surface Hub)
  • Apple iOS/iPadOS 14.0 and later
  • macOS 11.0 and later
  • Android 8.0 and later, including Samsung KNOX Standard 3.0 and higher
  • Linux Ubuntu Desktop (20.04 or 22.04 LTS on x86/64)
  • Chrome OS
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

By default, which users are allowed to enroll their supported device types to Intune?

A

By default, all users who are assigned an Intune license

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What can you configure that users must meet before they can enroll a device?

A

enrollment restrictions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

4

Which criteria enrollment restrictions can include?

A
  • Maximum number of devices that a user can enroll. (By default set to five devices per user).
  • Device platforms that can be enrolled:
  • Required operating system version for iOS, Android, Android work profile, and Windows devices (Minimum version//Maximum version)
  • Restrict enrollment of personally owned devices for iOS, Android, Android work profile, macOS, and personally owned devices for Windows 10/11.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

6

What are the enrollment options you can configure to manage device enrollment?

A
  • Terms and conditions. require that users accept the company’s terms and conditions before they can use the Company Portal
  • Enrollment restrictions. Device types that can be enrolled, block enrollment of personal devices, and restrict the number of devices that each user can enroll.
    Enable Apple device enrollment. You can control whether Apple devices can be enrolled (APN certificate required)
  • Corporate identifiers. list international mobile equipment identifier (IMEI) numbers and serial numbers to identify company-owned devices. You can also prevent enrollment of devices that aren’t company-owned.
  • Multifactor authentication When users enroll a device, you can require an additional verification method, such as a phone, PIN, or biometric data.
  • Device enrollment manager. Device enrollment manager (DEM) can enroll large numbers of devices. A restriction on the number of devices that a user can enroll doesn’t apply to DEM; DEM can enroll up to 1,000 devices.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How can you ensure that users enroll their devices?

A

can configure:
* a Security policy in Microsoft 365
or
* a Conditional access policy in Intune to allow access to company resources only from enrolled device

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

To enroll a windows device in MDM, if a it is already joined to on-premises AD DS which is synced to Microsoft Entra ID, what can you configure ?

A

the Enable automatic MDM enrollment using default Microsoft Entra credentials Group Policy setting