Microsoft Intune Interview Questions – Part 1: Fundamentals, Enrollment & Device Management

Microsoft Intune is Microsoft’s cloud-based endpoint management platform.

Contents hide
1 Microsoft Intune Interview Questions & Answers

For a senior System Administrator, knowing Intune means more than knowing how to create a configuration profile.

You should understand:

  • Intune architecture
  • MDM and MAM
  • Device enrollment
  • Microsoft Entra device identity
  • Automatic enrollment
  • Windows Autopilot
  • Device ownership
  • Enrollment restrictions
  • Company Portal
  • Device synchronization
  • Device inventory
  • Primary user
  • Device categories
  • Administrative scope
  • Troubleshooting enrollment failures
  • Hybrid environments
  • Co-management with Configuration Manager

This part focuses on Intune fundamentals, enrollment and device-management architecture.

Configuration profiles, compliance, endpoint security, application deployment and advanced troubleshooting will be covered separately so that the questions do not become repetitive.


Microsoft Intune Interview Questions & Answers

1. What is Microsoft Intune?

Microsoft Intune is a cloud-based endpoint management service used to manage and secure organizational devices, applications and corporate data.

It supports platforms such as:

  • Windows
  • macOS
  • iOS/iPadOS
  • Android
  • Linux in supported scenarios

For Windows environments, Intune can manage:

  • Device configuration
  • Security settings
  • Applications
  • Compliance
  • Windows updates
  • Device enrollment
  • Endpoint security

2. What is MDM?

MDM stands for:

Mobile Device Management

MDM allows an organization to manage device-level settings.

Examples:

  • Device configuration
  • Password requirements
  • Encryption requirements
  • Wi-Fi
  • VPN
  • Certificates
  • Security settings
  • Device restrictions

Conceptually:

Intune
   ↓
MDM
   ↓
Device Configuration
   ↓
Managed Device

3. What is MAM?

MAM stands for:

Mobile Application Management

MAM focuses on protecting corporate data at the application level rather than necessarily requiring full device management.

For example, an organization may want to protect Microsoft 365 data inside supported applications on a personal device without fully managing the entire device.

MAM is therefore particularly relevant to:

  • BYOD
  • Mobile applications
  • Corporate data protection

4. What is the difference between MDM and MAM?

MDMMAM
Manages the deviceManages/protects application data
Device-level controlsApplication/data-level controls
Device enrollment commonly involvedCan support scenarios where full device management isn’t appropriate
Encryption/configuration/device restrictionsApp protection/data controls

A simple interview answer:

MDM manages the device; MAM focuses on protecting corporate data within supported applications.


5. What is Intune enrollment?

Enrollment is the process of registering a device with Intune so that Intune can manage it.

After enrollment, Intune can deliver applicable:

  • Policies
  • Configuration
  • Applications
  • Security settings
  • Compliance requirements

For Windows, Microsoft supports several enrollment approaches including automatic enrollment, Windows Autopilot, BYOD enrollment and co-management with Configuration Manager.


6. What is Microsoft Entra ID’s role in Intune?

Microsoft Entra ID provides identity and device-related capabilities that integrate closely with Intune.

For example, a Windows device can be:

  • Microsoft Entra joined
  • Microsoft Entra hybrid joined
  • Microsoft Entra registered

Intune then manages the device through MDM enrollment where applicable.

A simplified model is:

Microsoft Entra ID
       ↓
Identity + Device Identity
       ↓
Microsoft Intune
       ↓
Device Management

7. What is Microsoft Entra joined?

A Microsoft Entra joined Windows device is joined directly to Microsoft Entra ID rather than being joined to traditional on-premises Active Directory.

This model is commonly used for cloud-managed Windows devices.

Example:

Windows 11
     ↓
Microsoft Entra Join
     ↓
Intune Enrollment
     ↓
Cloud Management

It is particularly suitable for organizations moving toward cloud-native endpoint management.


8. What is Microsoft Entra hybrid joined?

Microsoft Entra hybrid join connects a Windows device to:

  • On-premises Active Directory
  • Microsoft Entra ID

The device remains joined to the organization’s traditional Active Directory while also having a Microsoft Entra device identity.

This is commonly encountered during:

  • Cloud migration
  • Intune adoption
  • Co-management
  • Hybrid identity deployments

9. What is Microsoft Entra registered?

Microsoft Entra registered devices are typically associated with users and are commonly used for scenarios such as:

  • BYOD
  • Personal devices
  • Accessing organizational resources

Registration is different from a traditional Active Directory domain join or Microsoft Entra join.


10. What is automatic enrollment in Intune?

Automatic enrollment allows eligible devices to enroll into Intune automatically when the configured enrollment conditions are met.

For Windows, automatic enrollment can be used in scenarios including:

  • Corporate devices
  • BYOD
  • Windows Autopilot
  • Group Policy-based enrollment
  • Co-management

Microsoft Entra and Intune enrollment configuration determine how the process works.


11. What is the difference between Microsoft Entra Join and Intune enrollment?

They are related but not identical.

Microsoft Entra Join

Establishes the device’s identity relationship with Microsoft Entra ID.

Intune Enrollment

Establishes device management through Intune.

A device can therefore have a Microsoft Entra identity and be enrolled into an MDM service.

For example:

Microsoft Entra Join
        +
Intune Enrollment
        ↓
Cloud-managed Windows device

12. What is Windows Autopilot?

Windows Autopilot is a cloud-based Windows deployment and provisioning technology.

It is designed to simplify deployment of organization-owned Windows devices.

Instead of creating and maintaining a traditional custom Windows image, an organization can use the OEM-installed Windows operating system and configure the device during the out-of-box experience.

Microsoft’s current guidance describes Autopilot as an organization-owned Windows deployment option and notes that it requires automatic enrollment.


13. What are the major Windows Autopilot scenarios?

Important scenarios include:

User-driven

The user signs in with their organizational account and the device is configured for the user.

Self-deploying

The device can be provisioned with minimal user interaction, depending on the supported scenario and hardware.

Pre-provisioning

IT or a partner can prepare the device before handing it to the user.

Hybrid Microsoft Entra join

Autopilot can also be used with Microsoft Entra hybrid joined devices in supported configurations.


14. What is an Autopilot deployment profile?

An Autopilot deployment profile defines how Windows should behave during the Autopilot deployment process.

It can control aspects of the deployment experience such as:

  • User-driven vs other supported deployment scenarios
  • Microsoft Entra join configuration
  • OOBE behavior
  • User experience settings
  • Device configuration options

The profile is assigned to appropriate device groups.


15. What is the Enrollment Status Page (ESP)?

The Enrollment Status Page is displayed during Windows provisioning and shows the progress of device configuration.

It can track deployment of:

  • Applications
  • Security policies
  • Certificates
  • Network configuration
  • Other required configuration

The purpose is to ensure the device reaches the expected state before the user receives normal access to the desktop.


16. Why is ESP important during Autopilot?

Consider this scenario:

New laptop
    ↓
Autopilot
    ↓
User signs in
    ↓
Required applications
    ↓
Security configuration
    ↓
Device ready

Without appropriate ESP configuration, the user might receive access to the desktop before important applications or policies have completed.

ESP helps control this provisioning experience.


17. What happens if an application gets stuck during ESP?

First determine whether the application is:

  • Required
  • Assigned to the device/user
  • Compatible with the deployment
  • Installing successfully
  • Reporting status correctly

Then investigate:

  1. Application assignment
  2. Detection rules
  3. Installation command
  4. Return code
  5. Dependency
  6. Network connectivity
  7. Intune Management Extension logs where applicable
  8. ESP logs

Do not immediately recreate the entire Autopilot deployment.


18. What is the Intune Company Portal?

Company Portal is the user-facing application and website used to provide access to organizational resources managed through Intune.

Depending on platform and configuration, users can:

  • Install available applications
  • View device information
  • Start supported device actions
  • Check compliance
  • Resolve certain enrollment issues

It provides a self-service experience for users.


19. What is device check-in in Intune?

A managed device periodically communicates with Intune to retrieve and report management information.

During synchronization, the device can receive:

  • Policy changes
  • Application assignments
  • Configuration updates
  • Other management instructions

The normal synchronization interval varies by platform and scenario.

For Windows, Microsoft currently documents an approximately eight-hour default periodic check-in interval, while administrators can trigger an immediate sync.


20. How can you force an Intune device to synchronize?

For a Windows device, the user can initiate a sync from:

Settings → Accounts → Access work or school → Connected account → Info → Sync

The administrator can also initiate a sync from the Intune admin center where supported.

This is useful when troubleshooting:

“I assigned a policy five minutes ago, but the device hasn’t received it.”


21. A user says an Intune policy isn’t applying. What should you check first?

Do not immediately recreate the policy.

Check:

  1. Is the device enrolled?
  2. Is the user/device in the assigned group?
  3. Is the policy actually assigned?
  4. Is there an exclusion?
  5. Is the platform correct?
  6. Are applicability rules excluding the device?
  7. Is another policy conflicting?
  8. Has the device synchronized?
  9. Is the device in the expected management state?
  10. Is there an error in Intune device status?

This is the basic Intune troubleshooting sequence.


22. What are enrollment restrictions?

Enrollment restrictions control which devices and users can enroll into Intune and under what conditions.

They can help control:

  • Platform availability
  • Device types
  • Enrollment scenarios
  • Device limits
  • Personally owned device enrollment

They are particularly important in large enterprises where unrestricted enrollment could create governance problems.


23. Why should organizations restrict personal-device enrollment?

Suppose an organization allows unrestricted BYOD enrollment.

Employees could potentially enroll:

Personal Laptop
Personal Tablet
Personal Phone
Old Device
Test Device

This can create:

  • Security concerns
  • Licensing issues
  • Support overhead
  • Privacy concerns
  • Compliance complexity

A good design defines exactly which BYOD scenarios are allowed.


24. What is a device enrollment manager (DEM)?

A Device Enrollment Manager account is a specialized Intune account used for enrolling multiple devices in supported enrollment scenarios.

It is useful for certain shared-device or bulk enrollment scenarios.

However, DEM is not a replacement for Windows Autopilot.

Microsoft specifically documents that DEM accounts don’t apply to Windows Autopilot.


25. What is a device limit restriction?

A device limit controls how many devices a user can enroll.

For example:

Maximum devices = 5

If the user already has the maximum number of enrolled devices, another enrollment may fail.

During troubleshooting, therefore check:

  • Existing devices
  • Enrollment restrictions
  • User’s device limit
  • Stale device objects

26. What is device ownership in Intune?

Intune can distinguish between ownership types such as:

  • Corporate
  • Personal

Ownership can influence:

  • Management behavior
  • Enrollment restrictions
  • Reporting
  • Application deployment
  • Compliance
  • Administrative decisions

Correct ownership classification is therefore important.


27. What is a primary user?

The primary user identifies the main user associated with a managed device in Intune.

This is particularly useful for:

  • Device ownership
  • User support
  • Reporting
  • User-based application assignment
  • Troubleshooting

However, the primary user should not automatically be treated as the only user who can use the device.

Shared devices can have different usage models.


28. What is a shared device?

A shared device is designed for multiple users rather than one dedicated user.

Examples:

  • Reception computers
  • Warehouse terminals
  • Training-room computers
  • Factory-floor devices
  • Shared kiosks

These devices require different management considerations than a personal assigned laptop.


29. How would you manage shared Windows devices with Intune?

I would first identify the usage model.

For example:

Shared workstation
      ↓
Multiple users
      ↓
Minimal personalization
      ↓
Required applications
      ↓
Restricted configuration
      ↓
Centralized management

Then configure appropriate:

  • Device configuration
  • Security policies
  • Application deployment
  • User experience
  • Sign-in behavior
  • Compliance requirements

The exact configuration depends on the business requirement.


30. What are device categories in Intune?

Device categories allow organizations to classify devices according to organizational needs.

For example:

Finance
HR
IT
Warehouse
Kiosk
Executive

Categories can be useful for:

  • Organization
  • Reporting
  • Group assignment strategies
  • Administrative workflows

They should be used consistently rather than creating unnecessary categories.


31. What is an Intune scope tag?

Scope tags help control which Intune objects administrators can see and manage.

They are useful in delegated administration.

For example:

Central IT
   ↓
All devices

Regional IT
   ↓
Regional devices

Scope tags help separate administrative visibility and management responsibilities.


32. What is the difference between scope tags and assignments?

They solve different problems.

Scope tags

Control administrative visibility/scope.

Assignments

Determine which users or devices receive a policy, application or profile.

A simple way to remember:

Scope Tag
→ Who can manage/see it?

Assignment
→ Who receives it?

33. What is the Intune Management Extension?

The Intune Management Extension, or IME, is a Windows component used for certain Intune management capabilities, particularly Win32 application deployment and PowerShell script execution.

It is different from the core MDM channel.

Therefore, when troubleshooting a Win32 application or PowerShell deployment, you may need to investigate IME behavior and logs.


34. What is the difference between MDM and the Intune Management Extension?

MDM

Uses the Windows MDM channel and configuration service provider mechanisms for supported management settings.

Intune Management Extension

Provides additional capabilities such as:

  • Win32 application deployment
  • PowerShell scripts
  • Certain advanced management tasks

Therefore:

Intune
 ├── MDM
 └── Management Extension

They complement each other rather than being identical.


35. What is co-management?

Co-management allows an organization to manage Windows devices using both:

  • Microsoft Configuration Manager
  • Microsoft Intune

This is useful during gradual modernization from traditional endpoint management to cloud management.

For example:

Existing Environment
        ↓
Configuration Manager
        +
Intune
        ↓
Gradual Cloud Transition

Microsoft documents co-management as one of the supported Windows enrollment approaches.


36. Why would an enterprise use co-management?

A large organization may have:

10,000 existing Windows devices

Immediately moving everything to Intune may not be practical.

Co-management allows the organization to gradually move workloads while continuing to use Configuration Manager where necessary.

Possible benefits include:

  • Gradual migration
  • Reduced migration risk
  • Existing Configuration Manager investment
  • Cloud-based management capabilities
  • Flexible workload transition

37. What is Windows Autopilot device registration?

Before an organization can use Autopilot deployment for a device, the device must be registered in the organization’s Autopilot service.

The registration allows the organization to associate the device with its tenant and apply the appropriate deployment configuration.

After registration:

Device
 ↓
Autopilot registration
 ↓
Deployment profile
 ↓
Windows OOBE
 ↓
Enrollment

38. A new company laptop does not receive the Autopilot profile. What do you check?

Check in this order:

1. Is the device registered?

Verify the device appears in Windows Autopilot.

2. Is the correct deployment profile assigned?

Check the device/group assignment.

3. Is the device group membership correct?

Verify dynamic/static group membership.

4. Is there an exclusion?

Check profile exclusions.

5. Is the device connected to the Internet?

Autopilot requires network connectivity during provisioning.

6. Is the device running a supported Windows version?

7. Is the expected deployment scenario configured?

Do not immediately delete and recreate the device.


39. What happens if an Autopilot device is registered but the user sees normal Windows OOBE?

Investigate:

Autopilot registration
        ↓
Device identity
        ↓
Profile assignment
        ↓
Profile processing
        ↓
Network connectivity
        ↓
OOBE

Important checks include:

  • Correct device registration
  • Correct tenant
  • Deployment profile assignment
  • Assignment timing
  • Internet connectivity
  • Windows version
  • Autopilot profile configuration

A registration record by itself does not guarantee that the desired profile has been applied.


40. What is Windows Autopilot pre-provisioning?

Pre-provisioning allows an administrator, OEM or partner to prepare a device before giving it to the end user.

The goal is to perform appropriate provisioning steps before the user receives the device.

Conceptually:

OEM / IT
   ↓
Autopilot Pre-provisioning
   ↓
Applications
Policies
Security
   ↓
User receives device

This can improve the user’s first-login experience.


41. What is the difference between Autopilot and traditional imaging?

Traditional imaging

Often involves:

Custom OS Image
      ↓
Deployment
      ↓
Drivers
      ↓
Applications
      ↓
Configuration

Autopilot

Uses the OEM Windows installation and cloud-based provisioning:

OEM Windows
     ↓
Autopilot
     ↓
Microsoft Entra
     ↓
Intune
     ↓
Policies + Applications

Autopilot therefore changes the provisioning model rather than simply being another imaging tool.


42. Can Windows Autopilot be used for BYOD?

Windows Autopilot is intended for organization-owned devices.

For personal/BYOD scenarios, Microsoft documents other Windows enrollment approaches such as automatic enrollment or user enrollment depending on the scenario.

This distinction is important in interviews.


43. A user enrolls a Windows device but it doesn’t appear correctly in Intune. What do you investigate?

I would check:

  1. Microsoft Entra device state
  2. Intune enrollment status
  3. User licensing
  4. MDM authority/configuration
  5. Enrollment restrictions
  6. Device limit
  7. User assignment
  8. Enrollment errors
  9. Device synchronization
  10. Whether the device is already managed by another MDM

The important point is to determine whether the failure is:

Identity
   OR
Enrollment
   OR
Management

rather than treating them as the same thing.


44. What happens if a device is already managed by another MDM provider?

A device generally cannot simply be fully managed by multiple competing MDM providers simultaneously.

For an organization moving to Intune, the existing MDM relationship may need to be removed or transitioned according to the supported migration process.

Microsoft’s Windows enrollment guidance specifically notes that devices managed by another MDM provider must be transitioned appropriately before being fully managed by Intune.


45. How would you troubleshoot an Intune enrollment failure?

Use a layered approach.

User
 ↓
License
 ↓
Enrollment configuration
 ↓
Microsoft Entra identity
 ↓
Enrollment restrictions
 ↓
Device state
 ↓
Network
 ↓
Intune service
 ↓
Device-side logs

Check:

  • User license
  • MDM scope
  • Enrollment restrictions
  • Device limit
  • Platform restriction
  • Microsoft Entra device state
  • Existing MDM relationship
  • Enrollment errors
  • Device connectivity
  • Intune service health

46. A user says “Intune is not syncing.” What should you ask?

First determine what “not syncing” means.

Ask:

  • Are policies missing?
  • Are applications missing?
  • Is hardware inventory stale?
  • Is compliance status stale?
  • Is the device visible in Intune?
  • When was the last check-in?
  • Can the device manually sync?
  • Are there enrollment errors?

This avoids troubleshooting the wrong component.


47. What is the difference between device check-in and compliance evaluation?

They are related but different.

Device check-in

The device communicates with Intune and can receive/report management information.

Compliance evaluation

Intune evaluates whether the device satisfies configured compliance requirements.

Conceptually:

Device Check-in
      ↓
Device reports state
      ↓
Intune evaluates compliance
      ↓
Compliant / Noncompliant

The compliance result can then be used by Microsoft Entra Conditional Access.


48. Why is Microsoft Entra Conditional Access important with Intune?

Intune can provide device compliance information to Microsoft Entra Conditional Access.

For example:

User
 ↓
Attempts access
 ↓
Conditional Access
 ↓
Check device state/compliance
 ↓
Allow or block according to policy

This allows organizations to make access decisions based partly on device security posture.


49. What happens when a device becomes noncompliant?

The exact behavior depends on the organization’s configured compliance actions and Conditional Access policies.

A typical flow is:

Device
 ↓
Compliance evaluation
 ↓
Noncompliant
 ↓
Notification / remediation
 ↓
Conditional Access may restrict access

Intune can apply configured actions for noncompliance, and Conditional Access can use the compliance state when integrated.


50. Design an Intune architecture for an organization with 5,000 Windows laptops.

I would design it around standardized cloud management rather than manually configuring individual devices.

A high-level architecture:

                    Microsoft Entra ID
                           |
                           |
                    Microsoft Intune
                           |
          +----------------+----------------+
          |                |                |
     Enrollment       Configuration      Compliance
          |                |                |
      Autopilot       Settings Catalog   Compliance
          |             Security          Policies
          |                |                |
          +----------------+----------------+
                           |
                    Managed Windows
                       Devices
                           |
                    Conditional Access
                           |
                  Microsoft 365 / Apps

I would establish:

Identity

  • Microsoft Entra join where appropriate
  • Hybrid join where required
  • Appropriate user/device groups

Enrollment

  • Automatic enrollment
  • Windows Autopilot
  • Enrollment restrictions
  • Device ownership strategy

Management

  • Configuration profiles
  • Settings Catalog
  • Security baselines
  • Endpoint security
  • Application deployment

Security

  • Compliance policies
  • Microsoft Entra Conditional Access
  • Microsoft Defender integration where required

Operations

  • Device inventory
  • Monitoring
  • Reporting
  • Standard troubleshooting procedures
  • Administrative delegation

Migration

For existing Configuration Manager environments:

  • Evaluate co-management
  • Define workload transition
  • Pilot with representative users/devices
  • Gradually expand deployment

Important Intune Troubleshooting Flow

When a Windows device is not behaving as expected:

1. Is the device enrolled?
          ↓
2. Is it correctly identified in Entra ID?
          ↓
3. Is it assigned to the required group?
          ↓
4. Is the policy/application assigned?
          ↓
5. Is there an exclusion?
          ↓
6. Is the device compliant?
          ↓
7. Has the device checked in?
          ↓
8. Did the device receive the policy?
          ↓
9. Did the local component process it?
          ↓
10. Is there a conflict or installation failure?

This troubleshooting sequence is much more useful in an interview than simply saying:

“I would force a sync.”


Quick Revision

TopicKey Point
IntuneCloud endpoint management
MDMDevice-level management
MAMApplication/data protection
Entra JoinCloud device identity
Hybrid JoinAD + Entra device identity
Entra RegisteredCommonly used for BYOD scenarios
EnrollmentRegisters device for management
Automatic EnrollmentAutomatically enrolls eligible devices
AutopilotCloud-based Windows provisioning
ESPTracks provisioning/configuration progress
Company PortalUser self-service experience
DCRNot applicable to Intune; this belongs to Azure Monitor
Device OwnershipCorporate/personal classification
Primary UserMain user associated with device
DEMSpecialized enrollment account
IMEAdditional Windows management channel
Co-managementConfiguration Manager + Intune
ComplianceDetermines whether device meets requirements
Conditional AccessCan use device compliance as an access signal
Scope TagAdministrative visibility/scope
AssignmentDetermines who/what receives a policy

Exam Answer Summary

1. What is Intune?

A cloud-based endpoint management platform for managing devices, applications and corporate data.

2. MDM vs MAM?

MDM manages devices; MAM focuses on application/data protection.

3. Entra Join vs Intune Enrollment?

Entra Join establishes the device identity relationship with Microsoft Entra ID; Intune enrollment establishes management through Intune.

4. What is Autopilot?

A cloud-based Windows provisioning technology that uses the OEM Windows installation and configures the device through the out-of-box experience.

5. What is ESP?

Enrollment Status Page shows and controls the progress of device provisioning before normal desktop access.

6. What is co-management?

Management of Windows devices using both Configuration Manager and Intune during a transition or hybrid management strategy.

7. What is a scope tag?

A mechanism for controlling administrative visibility and scope in Intune.

8. What is an assignment?

An assignment determines which users or devices receive a policy, profile, application or other configuration.


Senior Interview Tip

For an Intune interview, don’t describe Intune as simply:

“A cloud version of Group Policy.”

That answer is incomplete.

A better senior-level explanation is:

“Intune is a cloud endpoint-management platform that uses multiple management mechanisms, including Windows MDM and the Intune Management Extension, and integrates with Microsoft Entra ID, Conditional Access, Microsoft Defender and other Microsoft security services. For Windows, I would design enrollment using automatic enrollment and Autopilot where appropriate, apply configuration and security policies through appropriate Intune policy types, evaluate device compliance, and use Conditional Access to control access based on the device’s security state.”

That demonstrates understanding of the architecture, not just the portal.


Next Part

Continue the Microsoft Intune Interview Series

Complete Series: [Microsoft Intune Interview Questions & Answers – Complete Series] | Next Part →: [Part 2: Configuration Profiles, Security Baselines & Troubleshooting]

Part 2 – Microsoft Intune Configuration Profiles, Settings Catalog, Security Baselines & Policy Troubleshooting

The next part will focus specifically on:

  • Configuration profiles
  • Settings Catalog
  • Administrative Templates
  • Security Baselines
  • Policy assignment
  • User vs device targeting
  • Filters
  • Applicability rules
  • Policy conflicts
  • Policy precedence
  • Windows CSP concepts
  • Policy processing
  • Sync and refresh
  • Policy troubleshooting
  • Real-world configuration scenarios

Official Microsoft Intune Documentation

For the latest Microsoft Intune documentation, supported capabilities and current configuration guidance, refer to Microsoft Learn.

Microsoft Intune Documentation:
https://learn.microsoft.com/en-us/intune/

Microsoft’s documentation is the authoritative source for current Intune capabilities because enrollment methods, supported platforms, policies and management features can change over time. (Microsoft Learn)

Leave a Comment