nerdexam
Microsoft

MD-102 · Question #8

Case Study 2 - Contoso Ltd Overview Contoso, Ltd, is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York. Contoso has the users and computers shown…

The correct answer is C. From the Azure Active Directory blade in the Azure portal, configure the Mobility (MDM and MAM) settings. To enable automatic MDM (Intune) enrollment for Azure AD-joined Windows 10 devices, you must configure the Mobility (MDM and MAM) settings in the Azure Active Directory blade of the Azure portal. This sets the MDM user scope, which triggers automatic Intune enrollment when a…

Submitted by minji_kr· Apr 18, 2026Prepare infrastructure for devices

Question

Case Study 2 - Contoso Ltd Overview Contoso, Ltd, is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York. Contoso has the users and computers shown in the following table. The company has IT, human resources (HR), legal (LEG), marketing (MKG) and finance (FIN) departments. Contoso uses Microsoft Store for Business and recently purchased a Microsoft 365 subscription. The company is opening a new branch office in Phoenix. Most of the users in the Phoenix office will work from home. Existing Environment The network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD). All member servers run Windows Server 2016. All laptops and desktop computers run Windows 10 Enterprise. The computers are managed by using Microsoft System Center Configuration Manager. The mobile devices are managed by using Microsoft Intune. The naming convention for the computers is the department acronym, followed by a hyphen, and then four numbers, for example, FIN-6785. All the computers are joined to the on-premises Active Directory domain. Each department has an organization unit (OU) that contains a child OU named Computers. Each computer account is in the Computers OU of its respective department. Intune Configuration The domain has the users shown in the following table. User2 is a device enrollment manager (DEM) in Intune. The devices enrolled in Intune are shown in the following table. The device compliance policies in Intune are configured as shown in the following table. The device compliance policies have the assignments shown in the following table. The device limit restrictions in Intune are configured as shown in the following table. Requirements Planned Changes Contoso plans to implement the following changes:

  • Provide new computers to the Phoenix office users. The new computers have Windows 10 Pro

preinstalled and were purchased already.

  • Start using a free Microsoft Store for Business app named App1.
  • mplement co-management for the computers.

Technical Requirements Contoso must meet the following technical requirements:

  • Ensure that the users in a group named Group4 can only access Microsoft Exchange Online

from devices that are enrolled in Intune.

  • Deploy Windows 10 Enterprise to the computers of the Phoenix office users by using Windows

Autopilot.

  • Monitor the computers in the LEG department by using Windows Analytics.
  • Create a provisioning package for new computers in the HR department.
  • Block iOS devices from sending diagnostic and usage telemetry data.
  • Use the principle of least privilege whenever possible.
  • Enable the users in the MKG department to use App1.
  • Pilot co-management for the IT department.

You need to meet the technical requirements for the IT department. What should you do first?

Options

  • AFrom the Azure Active Directory blade in the Azure portal, enable Seamless single sign-on.
  • BFrom the Configuration Manager console, add an Intune subscription.
  • CFrom the Azure Active Directory blade in the Azure portal, configure the Mobility (MDM and MAM) settings.
  • DFrom the Microsoft Intune blade in the Azure portal, configure the Windows enrollment settings.

How the community answered

(37 responses)
  • A
    11% (4)
  • B
    5% (2)
  • C
    81% (30)
  • D
    3% (1)

Explanation

To enable automatic MDM (Intune) enrollment for Azure AD-joined Windows 10 devices, you must configure the Mobility (MDM and MAM) settings in the Azure Active Directory blade of the Azure portal. This sets the MDM user scope, which triggers automatic Intune enrollment when a Windows 10 device is joined to or registered with Azure AD. Option A (Seamless SSO) is for hybrid environments to reduce sign-in prompts. Option B (adding an Intune subscription via Configuration Manager) is for co-management scenarios. Option D (Windows enrollment settings in Intune) manages enrollment restrictions but does not enable automatic enrollment - that requires the Azure AD MDM scope setting.

Topics

#Azure AD Mobility#MDM configuration#Intune integration#Device enrollment

Community Discussion

No community discussion yet for this question.

Full MD-102 Practice