Q1. A company’s on-premises network has an Active Directory domain named Fabrikam.com, which contains 500 devices running macOS or Windows 8.1.
In addition, there are also devices running Windows 10 or Windows 11.
All of these devices are managed by Microsoft Configuration Manager, and the domain is synchronized with Microsoft Entra ID (formerly Azure Active Directory).
You plan to deploy Microsoft 365 E5 and enable co-management.
Which devices can be managed by co-management after deployment?
Show answer
Co-management is a mechanism that manages a single Windows client simultaneously with both Microsoft Configuration Manager and Microsoft Intune.
This feature supports Windows 10 and later clients, and Windows 8.1 and macOS are not eligible for co-management.
Therefore, only Windows 11 and Windows 10 devices can be co-managed after deployment.
It is important to accurately distinguish that the supported OSes for co-management are limited to Windows 10 and later.
Note that Azure Active Directory in the question has now been renamed to Microsoft Entra ID.
Co-management for Windows devices – Configuration Manager
Q2. You have a Microsoft 365 E5 subscription with the following identities registered.
User1 is a “User”, Group1 is a “Microsoft 365 group”, Group2 is a “Mail-enabled security group”, and Group3 is a “Distribution group”.
You create a new shared mailbox named Shared1.
Which identities can you add as members of Shared1?
| Name | Type |
|---|---|
| User1 | User |
| Group1 | Microsoft 365 group |
| Group2 | Mail-enabled security group |
| Group3 | Distribution group |
Show answer
For delegation to a shared mailbox, you can assign users and mail-enabled security groups.
On the other hand, Microsoft 365 groups and distribution groups cannot be specified as members of a shared mailbox.
Therefore, only User1 and Group2 can be added.
It is important to be able to distinguish that only users and mail-enabled security groups can be used as delegation targets.
Manage permissions for recipients in Exchange Online | Microsoft Learn
Q3. You operate a Microsoft 365 E5 tenant.
You plan to create your own Compliance Manager assessment template based on the ISO 27001:2013 template.
As a prerequisite, you need to export the existing template.
Which file format must you use for the exported template?
Show answer
In Compliance Manager, an Excel-format file is generated when you export an existing template.
Microsoft Learn also explains that downloading the current or an updated template produces an Excel file.
Therefore, among the options, XLSX is the correct answer.
It is important to correctly distinguish that the export format is not CSV, JSON, or XML.
Build and manage assessments in Microsoft Purview Compliance Manager | Microsoft Learn
Q4. You use a Microsoft 365 E5 subscription.
You need to create a new mail-enabled contact (mail contact).
Which admin portal should you use for this task?
Show answer
A mail-enabled contact is treated as an Exchange Online recipient, and the actual creation is done in the Exchange admin center.
However, because the Exchange admin center is not among the options, the most appropriate entry point to navigate there is the Microsoft 365 admin center.
You cannot create it in the Microsoft Entra admin center, Purview, or the SharePoint admin center.
It is important to grasp that managing mail recipients is within the Exchange administration domain.
Manage mail contacts in Exchange Online
Q5. You configure a data loss prevention (DLP) policy named DLP1 as shown in the following figure.
Using the dropdown menus, complete each statement based on the settings shown in the figure.
Show answer
Because DLP1’s matching condition is set to “any of these,” a document qualifies if either a credit card number is detected with a match accuracy of 85-100, or the document has a 1-year retention label applied.
However, retention labels can be used as a condition only for SharePoint and OneDrive, and cannot be used for Exchange email.
Therefore, the location where DLP1 cannot be applied is Exchange email, and the applicable documents are those that have either a credit card number or a 1-year label.
Data loss prevention policy reference | Microsoft Learn
Q6. The following administrative units, groups, and role assignments are configured.
Administrative unit AU1 contains Group1 and User2, and AU2 contains Group2, User3, and User4.
The member of Group1 is User1, and the members of Group2 are User2 and User4.
User2 is a Password Administrator scoped to AU1, User3 is a License Administrator scoped to the organization, and User1 and User4 have no roles assigned.
Determine whether each statement is correct.
| Category | Name | Content | Scope |
|---|---|---|---|
| Administrative unit | AU1 | Group1, User2 | |
| Administrative unit | AU2 | Group2, User3, User4 | |
| Group | Group1 | User1 | |
| Group | Group2 | User2, User4 | |
| User | User1 | No role | N/A |
| User | User2 | Password Administrator | AU1 |
| User | User3 | License Administrator | Organization |
| User | User4 | No role | N/A |
| Statement | Yes | No | |
|---|---|---|---|
| User2 can reset User1’s password | |||
| User2 can reset User4’s password | |||
| User3 can assign a license to User1 |
Show answer
In the current official specification, when a group is added to an administrative unit, the group itself becomes managed, but the users who are members of the group are not automatically included in the management scope.
Therefore, User2, who is a Password Administrator scoped to AU1, cannot reset the password of User1 (via Group1) or User4 (who belongs to a different administrative unit).
On the other hand, User3, who is a License Administrator scoped to the organization, can assign a license to User1.
Therefore, the determinations are No, No, and Yes.
Add users, groups, or devices to an administrative unit
Q7. You have a Microsoft 365 tenant that contains devices enrolled in Microsoft Intune.
The devices are configured as follows: Device1 is Windows 10, Device2 is Android, and Device3 is iOS.
In Microsoft Endpoint Manager, you plan to perform the management tasks of deploying a VPN connection using a VPN device configuration profile and configuring security settings using an Endpoint Protection device configuration profile.
To proceed with these management tasks, you need to identify the target devices for each.
To which devices can each profile be applied?
| Name | Platform |
|---|---|
| Device1 | Windows 10 |
| Device2 | Android |
| Device3 | iOS |
Show answer
The VPN device configuration profile supports multiple platforms such as Windows, Android, and iOS, so the targets are all of Device1, Device2, and Device3.
On the other hand, because the Endpoint Protection device configuration profile primarily targets Windows and macOS, only Device1 (Windows 10) applies in this table.
It is important to accurately distinguish that the supported platforms differ by profile type.
Device features and settings in Microsoft Intune – Microsoft Intune | Microsoft Learn
Q8. You have a Microsoft 365 subscription, and your network uses the IP address space 51.40.15.0/24.
Recently, an Exchange Online administrator created a role named Role1 from a computer on the network.
Using audit log search, you need to identify the name of the administrator who performed this operation.
In audit log search, which activity should you search for and by which field should you filter?
To answer, select the appropriate options in the answer area.
Show answer
Because creating a role is a management operation not limited to a specific workload, it is appropriate to first set the search target to “Show results for all activities.”
Furthermore, because you need to narrow down by the created role name Role1, you filter by the “Detail” field rather than by user name or IP address.
This allows you to check the operation target name within the audit record and identify the administrator who created Role1.
It is important to distinguish what to search for in the audit log and which column to filter by.
Search the audit log
Q9. Your network has an on-premises Active Directory domain, and the domain controllers run Windows Server 2019.
The forest and domain functional levels are Windows Server 2012 R2.
The domain contains 100 computers running Windows 10 and a member server named Server1 running Windows Server 2012 R2.
You plan to use Server1 to manage the domain and configure Group Policy settings for Windows 10, and you install the Group Policy Management Console (GPMC) on Server1.
You need to configure Windows Update for Business Group Policy settings on Server1.
As a solution, you upgrade Server1 to Windows Server 2019.
Does this achieve the goal?
Show answer
This solution achieves the goal.
Microsoft Learn explicitly lists Windows Server 2019 as capable of configuring Windows Update for Business client policies.
By upgrading Server1 to Windows Server 2019 and using the GPMC, you can manage the Windows Update for Business Group Policy settings for Windows 10.
The question addresses that what matters is whether the management endpoint’s OS is supported, not the functional level.
Configure Windows Update client policies | Microsoft Learn
Q10. You use Microsoft Defender for Endpoint with a Microsoft 365 E5 subscription.
The subscription contains the devices Device1 (Windows 11), Device2 (Android), and Device3 (Linux).
You need to create two endpoint security policies: Policy1 (template: Microsoft Defender Antivirus) and Policy2 (template: Device control).
To which devices can each policy be applied?
To answer, select the appropriate options in the answer area.
| Name | Platform |
|---|---|
| Device1 | Windows 11 |
| Device2 | Android |
| Device3 | Linux |
| Name | Template |
|---|---|
| Policy1 | Microsoft Defender Antivirus |
| Policy2 | Device control |
Show answer
Policy1’s template, Microsoft Defender Antivirus, is configured for Windows in Intune.
Therefore, only Device1 (Windows 11) can be applied in this question.
On the other hand, Policy2’s Device control supports multiple platforms, and in this question, Device1 or Device2 is the applicable target.
It is important to distinguish that the applicable platforms differ for each endpoint security policy.
Endpoint security in Microsoft Intune – Microsoft Intune | Microsoft Learn
