MD-102 · Question #130
You have a Microsoft 365 subscription that contains a user named User1 and uses Microsoft Intune Suite. You use Microsoft Intune to manage devices that run Windows 11. User provides remote support…
The correct answer is C. an account protection policy. An account protection policy (under Endpoint Security in Intune) is the correct tool. Specifically, the 'Local user group membership' feature within account protection policies allows administrators to add Azure AD users or groups to local Windows groups such as Remote Desktop…
Question
You have a Microsoft 365 subscription that contains a user named User1 and uses Microsoft Intune Suite. You use Microsoft Intune to manage devices that run Windows 11. User provides remote support for 75 devices in the marketing department. You need to add User1 to the Remote Desktop Users group on each marketing department device. What should you configure?
Options
- Aan app configuration policy
- Ba device compliance policy
- Can account protection policy
- Da device configuration profile
How the community answered
(24 responses)- A4% (1)
- B8% (2)
- C83% (20)
- D4% (1)
Explanation
An account protection policy (under Endpoint Security in Intune) is the correct tool. Specifically, the 'Local user group membership' feature within account protection policies allows administrators to add Azure AD users or groups to local Windows groups such as Remote Desktop Users on managed devices. This enables User1 to be added to the Remote Desktop Users group across all 75 marketing devices via policy, without manual intervention. A device configuration profile (D) could also technically do this via custom settings, but account protection policy has a dedicated, purpose-built UI for local group membership management. App configuration (A) and compliance (B) policies do not manage local group memberships.
Topics
Community Discussion
No community discussion yet for this question.