nerdexam
Microsoft

SC-300 · Question #405

Hotspot Question Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains computers that run Windows 11. You have a Microsoft 365 E5 subscription…

The correct answer is Domain:: Intune Connector for Active Directory; Intune:: Modify the mobile device management (MDM) user scope. Hybrid Join + Intune Enrollment - Exam Explanation --- Dropdown 1: Software to deploy to the Domain Correct: Intune Connector for Active Directory The Intune Connector for Active Directory (formerly called the ODJ Connector) is required specifically for hybrid Azure AD join…

Submitted by the_admin· Mar 6, 2026Implement identity management solution

Question

Hotspot Question Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains computers that run Windows 11. You have a Microsoft 365 E5 subscription. You plan to enable hybrid join and enroll the computers in Microsoft Intune. You need to recommend the software that should be deployed to the domain, and the actions that should be performed in Intune. What should you include in the recommendation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Answer:

Answer Area

  • Domain:Intune Connector for Active Directory
    Intune Connector for Active DirectoryMicrosoft Entra ConnectThe Microsoft Entra provisioning agent
  • Intune:Modify the mobile device management (MDM) user scope.
    Create a Windows Autopilot device preparation policy.Modify the mobile device management (MDM) user scope.Modify the Windows Information Protection (WIP) user scope.

Explanation

Hybrid Join + Intune Enrollment - Exam Explanation


Dropdown 1: Software to deploy to the Domain

Correct: Intune Connector for Active Directory

The Intune Connector for Active Directory (formerly called the ODJ Connector) is required specifically for hybrid Azure AD join scenarios where Autopilot needs to join devices to an on-premises AD domain. It acts as a bridge - installed on a domain-joined server on-premises - allowing Intune to issue offline domain join (ODJ) requests so that devices can be joined to the on-prem domain during Autopilot provisioning.

Why the others are wrong:

  • Microsoft Entra Connect (formerly Azure AD Connect) - This synchronizes identities from on-premises AD to Entra ID. It's a prerequisite for hybrid identity broadly, but it's already assumed to be in place for hybrid environments and is not deployed specifically to enable Intune enrollment of hybrid-joined computers. The question asks what needs to be added for this plan.
  • Microsoft Entra Provisioning Agent - This is used for cloud sync (a lighter alternative to Entra Connect) or for provisioning to on-premises AD from Entra ID. It doesn't facilitate the Intune <-> on-prem AD communication needed for hybrid Autopilot joins.

Key concept: The Intune Connector for AD is the only component purpose-built for enabling Intune-driven hybrid AD join.


Dropdown 2: Action to perform in Intune

Correct: Modify the mobile device management (MDM) user scope.

To enroll Windows 11 devices into Intune automatically (via hybrid join), you must configure MDM automatic enrollment in Entra ID. The MDM user scope controls which users' devices are automatically enrolled in Intune when they authenticate. Setting it to All (or a specific group) triggers automatic MDM enrollment upon hybrid join completion.

Why the others are wrong:

  • Create a Windows Autopilot device preparation policy - Autopilot Device Preparation is a newer, simplified Autopilot flow. It's not required for standard hybrid join enrollment of existing domain computers. The scenario describes enrolling existing Windows 11 domain computers, not provisioning new devices through Autopilot.
  • Modify the Windows Information Protection (WIP) user scope - WIP is a data protection feature for classifying and protecting corporate data. It has nothing to do with enabling device enrollment. Changing the WIP scope does not cause devices to enroll in Intune.

Key concept: MDM automatic enrollment is gated by the MDM user scope setting in Entra ID -> Mobility (MDM and WIP). Without setting this, devices that complete hybrid join will not automatically enroll into Intune.


Summary

ComponentPurpose
Intune Connector for ADOn-prem server agent enabling Intune to issue domain join requests
MDM user scope (set to All/Group)Triggers automatic Intune enrollment post-hybrid-join

Topics

#Hybrid Identity#Device Management#Intune Enrollment#Azure AD Join

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice