SC-300 · Question #405
Hotspot Question Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains computers that run Windows 11. You have a Microsoft 365 E5 subscription…
The correct answer is Domain:: Intune Connector for Active Directory; Intune:: Modify the mobile device management (MDM) user scope. Hybrid Join + Intune Enrollment - Exam Explanation --- Dropdown 1: Software to deploy to the Domain Correct: Intune Connector for Active Directory The Intune Connector for Active Directory (formerly called the ODJ Connector) is required specifically for hybrid Azure AD join…
Question
Answer Area
- Domain:Intune Connector for Active DirectoryIntune Connector for Active DirectoryMicrosoft Entra ConnectThe Microsoft Entra provisioning agent
- Intune:Modify the mobile device management (MDM) user scope.Create a Windows Autopilot device preparation policy.Modify the mobile device management (MDM) user scope.Modify the Windows Information Protection (WIP) user scope.
Explanation
Hybrid Join + Intune Enrollment - Exam Explanation
Dropdown 1: Software to deploy to the Domain
Correct: Intune Connector for Active Directory
The Intune Connector for Active Directory (formerly called the ODJ Connector) is required specifically for hybrid Azure AD join scenarios where Autopilot needs to join devices to an on-premises AD domain. It acts as a bridge - installed on a domain-joined server on-premises - allowing Intune to issue offline domain join (ODJ) requests so that devices can be joined to the on-prem domain during Autopilot provisioning.
Why the others are wrong:
- Microsoft Entra Connect (formerly Azure AD Connect) - This synchronizes identities from on-premises AD to Entra ID. It's a prerequisite for hybrid identity broadly, but it's already assumed to be in place for hybrid environments and is not deployed specifically to enable Intune enrollment of hybrid-joined computers. The question asks what needs to be added for this plan.
- Microsoft Entra Provisioning Agent - This is used for cloud sync (a lighter alternative to Entra Connect) or for provisioning to on-premises AD from Entra ID. It doesn't facilitate the Intune <-> on-prem AD communication needed for hybrid Autopilot joins.
Key concept: The Intune Connector for AD is the only component purpose-built for enabling Intune-driven hybrid AD join.
Dropdown 2: Action to perform in Intune
Correct: Modify the mobile device management (MDM) user scope.
To enroll Windows 11 devices into Intune automatically (via hybrid join), you must configure MDM automatic enrollment in Entra ID. The MDM user scope controls which users' devices are automatically enrolled in Intune when they authenticate. Setting it to All (or a specific group) triggers automatic MDM enrollment upon hybrid join completion.
Why the others are wrong:
- Create a Windows Autopilot device preparation policy - Autopilot Device Preparation is a newer, simplified Autopilot flow. It's not required for standard hybrid join enrollment of existing domain computers. The scenario describes enrolling existing Windows 11 domain computers, not provisioning new devices through Autopilot.
- Modify the Windows Information Protection (WIP) user scope - WIP is a data protection feature for classifying and protecting corporate data. It has nothing to do with enabling device enrollment. Changing the WIP scope does not cause devices to enroll in Intune.
Key concept: MDM automatic enrollment is gated by the MDM user scope setting in Entra ID -> Mobility (MDM and WIP). Without setting this, devices that complete hybrid join will not automatically enroll into Intune.
Summary
| Component | Purpose |
|---|---|
| Intune Connector for AD | On-prem server agent enabling Intune to issue domain join requests |
| MDM user scope (set to All/Group) | Triggers automatic Intune enrollment post-hybrid-join |
Topics
Community Discussion
No community discussion yet for this question.