You're the systems administrator for an international sports equipment retail company. The company requires that the Windows 11 laptops for employees be replaced with new Windows 11 laptops every 3 years.In addition, the company requires the following:When the employees log into their new laptops, all the existing user and application settings need to be in place.There must be a separation of corporate and employee data.Data must be automatically encrypted with Azure Rights Management.Which of the following features would BEST meet the company's requirements?answerAzure Active Directory single sign-on (SSO)Microsoft IntuneEnterprise State RoamingWindows Information Protection (WIP)
Question
You're the systems administrator for an international sports equipment retail company. The company requires that the Windows 11 laptops for employees be replaced with new Windows 11 laptops every 3 years.In addition, the company requires the following:When the employees log into their new laptops, all the existing user and application settings need to be in place.There must be a separation of corporate and employee data.Data must be automatically encrypted with Azure Rights Management.Which of the following features would BEST meet the company's requirements?answerAzure Active Directory single sign-on (SSO)Microsoft IntuneEnterprise State RoamingWindows Information Protection (WIP)
Solution
The best features to meet the company's requirements would be a combination of Microsoft Intune, Enterprise State Roaming, and Windows Information Protection (WIP).
-
Microsoft Intune: This is a cloud-based service that focuses on mobile device management (MDM) and mobile application management (MAM). It can help manage the laptops and ensure they are replaced every 3 years as required by the company.
-
Enterprise State Roaming: This feature would help with the requirement of having all the existing user and application settings in place when employees log into their new laptops. It provides a user with a unified experience across their Windows devices by syncing user and app settings.
-
Windows Information Protection (WIP): This feature helps to protect against potential data leakage without otherwise interfering with the employee experience. WIP also helps to protect enterprise apps and data against accidental data leak on enterprise-owned devices and personal devices that employees bring to work.
However, Azure Active Directory single sign-on (SSO) would also be beneficial as it simplifies user access to their applications from anywhere. It would not directly meet the requirements stated but would be a good feature to have for the overall user experience.
Similar Questions
Listen to exam instructionsYou're the systems administrator for an international trading company that uses Azure Active Directory (AD) and Microsoft Intune to manage their mobile devices. All company-owned mobile devices are registered in Azure AD and enrolled in Microsoft Intune.Many company-owned laptops are currently running Windows 10 and are enrolled in Microsoft Intune. You want to identify which of these laptops can be upgraded to Windows 11.SOLUTION: You create a device compliance policy and assign the policy to the laptops. After 24 hours, you view the device compliance report in Intune.DragYesNoDropDoes this solution help you identify which laptops can be upgraded?
Listen to exam instructionsAll your company-owned Windows laptops are currently enrolled in Intune for management purposes.One of your employees is on long-term leave and you have assigned the employee's laptop to someone else. You want the new laptop owner to be assigned as the primary user the first time they log in.Which of the following Intune security features could you easily use remotely to meet your logon requirement?answerAutopilot resetRemote wipeRemote lockCustom policy
You're the systems administrator for an international sports equipment retail company that uses Azure Active Directory (AD) and Microsoft Intune to manage their mobile devices. All company-owned Windows 11 mobile devices are registered in Azure AD and enrolled in Microsoft Intune.You decide that you want to create an Intune conditional access policy that:Applies the policy to the Office 365, Microsoft Teams, and SharePoint cloud apps.Assigns the policy to Windows platforms.Requires the Windows 11 devices to be marked as Compliant.To properly configure this Intune conditional access policy, you need to perform several tasks. From the list of tasks on the left, drag the tasks to the right in the proper order for creating the policy. (Not all listed tasks are part of creating the policy.)Give the policy a name.Enable the policy.Send an email to the users.Assign users and user groups.Select cloud apps or user actions.Grant or block access based on controls.Select conditions.Set up network fencing.Determine the OS version.move rightmove left
You want to use a Microsoft tool to provide remote assistance on Windows 11 laptops assigned to your employees. You also want limit the administrative tasks that Level 1 Help Desk support staff can perform on a remotely-connected laptop.You have Intune installed and are using Azure Active Directory to manage users and accounts.Which of the following tools would BEST meet your remote connection requirements?answerQuick AssistRemote HelpRemote AssistanceRemote Desktop
You're the systems administrator for a fashion design company that uses Azure Active Directory (AD) and Microsoft Intune to manage their mobile devices. All company-owned mobile devices are registered in Azure AD and enrolled in Microsoft Intune.You've created the following Azure AD device groups:Win11dev: All company-owned Windows 11 mobile devicesiPadProdev: All company-owned iPad Pro tabletsAndroiddev: All company-owned Android mobile devicesYou've created a Microsoft App Store device configuration profile that restricts several options for employee management of apps in the Microsoft Store. These setting apply on the employees' managed Windows 11 mobile devices.However, when you test the device profile on a limited number of the Windows 11 mobile devices, you find that the device profile configurations aren't being applied.SOLUTION: You check the assignments for the device profile and notice that there are no assignments currently configured. On the Include tab, you assign the Win11dev device group to the device profile.DragYesNoDropDoes this action solve the issue of the unapplied device configuration profile?
Upgrade your grade with Knowee
Get personalized homework help. Review tough concepts in more detail, or go deeper into your topic by exploring other relevant questions.