nerdexam
Microsoft

MS-102 · Question #445

You have a Microsoft 365 E5 subscription that contains 500 users. Two hundred users have personal devices that run either Android, Windows 10, or macOS. Three hundred users have corporate-owned…

The correct answer is A. a dynamic device group. To apply separate device policies based on ownership (personal vs. corporate) with minimal administrative overhead, create dynamic device groups. These groups automatically categorize devices based on their attributes, allowing for targeted policy assignment.

Submitted by rachelw· Apr 18, 2026Deploy and manage a Microsoft 365 tenant

Question

You have a Microsoft 365 E5 subscription that contains 500 users. Two hundred users have personal devices that run either Android, Windows 10, or macOS. Three hundred users have corporate-owned devices that run either Windows 10 or macOS. You plan to configure device enrollment. You need to ensure that you can apply separate policies to the corporate-owned devices and the personal devices. The solution must minimize administrative effort. What should you create first?

Options

  • Aa dynamic device group
  • Ba dynamic user group
  • Ca deployment package
  • Da Microsoft 365 group

How the community answered

(50 responses)
  • A
    62% (31)
  • B
    6% (3)
  • C
    20% (10)
  • D
    12% (6)

Why each option

To apply separate device policies based on ownership (personal vs. corporate) with minimal administrative overhead, create dynamic device groups. These groups automatically categorize devices based on their attributes, allowing for targeted policy assignment.

Aa dynamic device groupCorrect

Dynamic device groups in Azure AD or Microsoft Intune automatically update membership based on device attributes like ownership type (e.g., 'Corporate' or 'Personal'). This allows administrators to define policies once and have them automatically applied to the correct set of devices as they enroll, fulfilling the requirement for separate policies with minimal effort.

Ba dynamic user group

A dynamic user group categorizes users, not devices, and therefore cannot be used to apply policies specifically to personal or corporate devices.

Ca deployment package

A deployment package is used for software distribution, not for defining device enrollment policies or grouping devices for policy application.

Da Microsoft 365 group

A Microsoft 365 group is primarily for collaboration and user access to shared resources, not for dynamically grouping devices based on ownership for policy enforcement.

Concept tested: Dynamic device group for policy targeting

Source: https://learn.microsoft.com/en-us/azure/active-directory/enterprise-users/groups-create-dynamic

Topics

#Dynamic device groups#Intune device enrollment#Device management#Policy application

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice