MS-102 · Question #508
You have a Microsoft 365 tenant. All users are assigned the Enterprise Mobility + Security license. You need to ensure that when users join their device to Microsoft Azure Active Directory (Azure…
The correct answer is D. MDM User scope from the Azure Active Directory admin center. To enable automatic MDM enrollment in Microsoft Intune when users join devices to Azure AD, you must configure the MDM User scope in the Azure Active Directory admin center (under Mobility > Microsoft Intune). Setting this to 'All' or a specific group triggers automatic Intune…
Question
You have a Microsoft 365 tenant. All users are assigned the Enterprise Mobility + Security license. You need to ensure that when users join their device to Microsoft Azure Active Directory (Azure AD), the device is enrolled in Microsoft Intune automatically. What should you configure?
Options
- AEnrollment restrictions from the Intune admin center
- Bdevice enrollment managers from the Intune admin center
- CMAM User scope from the Azure Active Directory admin center
- DMDM User scope from the Azure Active Directory admin center
How the community answered
(29 responses)- A7% (2)
- B3% (1)
- C14% (4)
- D76% (22)
Explanation
To enable automatic MDM enrollment in Microsoft Intune when users join devices to Azure AD, you must configure the MDM User scope in the Azure Active Directory admin center (under Mobility > Microsoft Intune). Setting this to 'All' or a specific group triggers automatic Intune enrollment when a device is Azure AD joined. MAM User scope (C) controls Mobile Application Management enrollment for personal/BYOD devices and does not apply to Azure AD Join scenarios. Enrollment restrictions (A) define what device types or platforms are allowed to enroll but do not enable automatic enrollment. Device enrollment managers (B) allow specific accounts to enroll many devices but are not the mechanism that triggers auto-enrollment on Azure AD join.
Topics
Community Discussion
No community discussion yet for this question.