exam questions

Exam MD-102 All Questions

View all questions & answers for the MD-102 exam

Exam MD-102 topic 1 question 42 discussion

Actual exam question from Microsoft's MD-102
Question #: 42
Topic #: 1
[All MD-102 Questions]

HOTSPOT -
You have an Azure AD tenant named contoso.com that contains the users shown in the following table.

You have a computer named Computer1 that runs Windows 10. Computer1 is in a workgroup and has the local users shown in the following table.

UserA joins Computer1 to Azure AD by using [email protected].
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
letters1234
Highly Voted 1 year, 8 months ago
Should be YNN, CDA is admin within azure portal. SA is also azure role and doesn't have local admin rights to make changes.
upvoted 34 times
Futfuyfyjfj
1 year, 7 months ago
Wat not YNY. (Cloud) Device administrator role : https://techcommunity.microsoft.com/t5/microsoft-intune/as-a-device-admin-global-admin-how-can-i-install-software/m-p/2025358
upvoted 4 times
SajjH
8 months, 2 weeks ago
Cloud Device Admin and Device/Global Admin are not same.
upvoted 1 times
...
Alscoran
1 year, 6 months ago
I don't think they can install anything on the local machine: https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#cloud-device-administrator
upvoted 2 times
...
ExamKiller020
1 year, 7 months ago
The link you provided doesnt clarify anything. In the article is probably reffered to the 'Azure AD Joined Device Local Administrator' role and not the Cloud device Administrator role
upvoted 3 times
NoursBear
1 year, 3 months ago
This article does not make sense, the person says they are global admin and device admin, the global admin group would be automatically inserted in the local admin group
upvoted 1 times
...
...
...
...
JP1900
Highly Voted 1 year, 8 months ago
letters1234 is correct, it is YNN.
upvoted 14 times
...
hieunm2411
Most Recent 2 months, 2 weeks ago
The Security Administrator can indirectly configure the firewall and defender on a device, but the question didn't mention the device enrolled in Intune so the correct answer is YNN.
upvoted 1 times
...
Tr619899
5 months ago
YNN is the answer
upvoted 2 times
...
LionelDerBoven
7 months, 2 weeks ago
Y N N When device is joined in AAD it wil get local admin rights (for now). Security admin is for administration of security feature in entra etc.. No local admin rights. Same with cloud device administrator.
upvoted 2 times
...
oopspruu
8 months, 1 week ago
YNN As of now, user peforming Join will become an admin. This can be managed in future with a preview setting currently rolling out. Cloud Device Admin has only permission for Entra Device section and not the actual device. Security Admin has no permission to any device management.
upvoted 2 times
...
mail2bala3011
1 year ago
https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference#security-administrator
upvoted 1 times
...
Softeng
1 year, 2 months ago
YNN Cloud Device Administrator role does not grant permissions to manage any other properties on the device: https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference#cloud-device-administrator
upvoted 3 times
...
kaushik07
1 year, 2 months ago
User1 have no roles assigned, but part of local "users" group, when UserA join the device1 using the user1 account it doesn't automatically elivate the user1's roles, user1 will still be an local user, will not become a member of local admins group.
upvoted 6 times
...
Merrybob
1 year, 2 months ago
NYN is correct
upvoted 6 times
...
NoursBear
1 year, 3 months ago
Manage regular users By default, Microsoft Entra ID adds the user performing the Microsoft Entra join to the administrator group on the device. If you want to prevent regular users from becoming local administrators, you have the following options: Windows Autopilot - Windows Autopilot provides you with an option to prevent primary user performing the join from becoming a local administrator by creating an Autopilot profile. Bulk enrollment - a Microsoft Entra join that is performed in the context of a bulk enrollment happens in the context of an autocreated user. Users signing in after a device has been joined aren't added to the administrators group. answers are correct
upvoted 2 times
NoursBear
1 year, 3 months ago
I didn't mean the answers are correct from the question, but with YNN above
upvoted 4 times
...
...
NoursBear
1 year, 3 months ago
After further research, I have read that a cloud device administrator gets admin rights on the devices that are joined but NOT if they are hybrid joined. So now I don't know anymore about the 3rd answer. When reading about the role itself, it's not mentioning any of this.
upvoted 1 times
NoursBear
1 year, 3 months ago
I am now convinced that there is a confusion with the 2 roles "Microsoft Entra Joined Device Local Administrator" which is automatically added to the local devices and "Cloud Device Administrator" and I think this confusion is also on Microsoft community blogs, some MS employees are answering wrong stuff so I am now satisfied with a No for 3rd answer
upvoted 1 times
...
...
belyo
1 year, 4 months ago
i would vote for NO,NO,NO during the join operation security principals of the user are temporary added to local admin group, not the user itself, even if not so thats temporary security admin cannot configure firewall & defender on that computer cloud device admin cant install anything
upvoted 3 times
...
yosry
1 year, 4 months ago
the first answer is NO: tested it on my tenant (joining a device using a user profile does not add it to the Administrators Group) Proof that the second answer is YES: https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference#security-administrator this is proof that the third answer is NO: https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference#cloud-device-administrator
upvoted 12 times
...
iTomi
1 year, 4 months ago
YES At the time of Microsoft Entra join, we add the following security principals to the local administrators group on the device: * The Microsoft Entra Global Administrator role * The Microsoft Entra Joined Device Local Administrator role * The user performing the Microsoft Entra join https://learn.microsoft.com/en-us/entra/identity/devices/assign-local-admin NO Question is ”[email protected] can configure the firewall and Microsoft Defender ON COMPUTER1.” Security administrator doesn’t have local admin rights to modify firewall and defender settings ON COMPUTER1. NO This is a privileged role. Users in this role can enable, disable, and delete devices in Microsoft Entra ID and read Windows 10 BitLocker keys (if present) in the Azure portal. The role does not grant permissions to manage any other properties on the device. https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference#cloud-device-administrator
upvoted 5 times
...
NoursBear
1 year, 4 months ago
Cloud Device Administrator: With Cloud Device administrator role, you can Delete/Disable/Enable devices in Azure Active Directory but you cannot Add/Remove Users in the directory. With User administrator role, you can Add/Remove users in Azure AD but cannot Delete/Disable/Enable the devices.
upvoted 1 times
NoursBear
1 year, 4 months ago
Security Administrator Can read security information and reports, and manage configuration in Microsoft Entra ID and Office 365. It is a Priviledged role, but unable to understand what that actually means
upvoted 1 times
...
...
benpatto
1 year, 5 months ago
By default, Microsoft Entra ID adds the user performing the Microsoft Entra join to the administrator group on the device. If you want to prevent regular users from becoming local administrators, you have the following options:
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago