Microsoft Intune is Microsoft’s cloud-based endpoint management platform.
For a senior System Administrator, knowing Intune means more than knowing how to create a configuration profile.
You should understand:
- Intune architecture
- MDM and MAM
- Device enrollment
- Microsoft Entra device identity
- Automatic enrollment
- Windows Autopilot
- Device ownership
- Enrollment restrictions
- Company Portal
- Device synchronization
- Device inventory
- Primary user
- Device categories
- Administrative scope
- Troubleshooting enrollment failures
- Hybrid environments
- Co-management with Configuration Manager
This part focuses on Intune fundamentals, enrollment and device-management architecture.
Configuration profiles, compliance, endpoint security, application deployment and advanced troubleshooting will be covered separately so that the questions do not become repetitive.
Microsoft Intune Interview Questions & Answers
1. What is Microsoft Intune?
Microsoft Intune is a cloud-based endpoint management service used to manage and secure organizational devices, applications and corporate data.
It supports platforms such as:
- Windows
- macOS
- iOS/iPadOS
- Android
- Linux in supported scenarios
For Windows environments, Intune can manage:
- Device configuration
- Security settings
- Applications
- Compliance
- Windows updates
- Device enrollment
- Endpoint security
2. What is MDM?
MDM stands for:
Mobile Device Management
MDM allows an organization to manage device-level settings.
Examples:
- Device configuration
- Password requirements
- Encryption requirements
- Wi-Fi
- VPN
- Certificates
- Security settings
- Device restrictions
Conceptually:
Intune
↓
MDM
↓
Device Configuration
↓
Managed Device
3. What is MAM?
MAM stands for:
Mobile Application Management
MAM focuses on protecting corporate data at the application level rather than necessarily requiring full device management.
For example, an organization may want to protect Microsoft 365 data inside supported applications on a personal device without fully managing the entire device.
MAM is therefore particularly relevant to:
- BYOD
- Mobile applications
- Corporate data protection
4. What is the difference between MDM and MAM?
| MDM | MAM |
|---|---|
| Manages the device | Manages/protects application data |
| Device-level controls | Application/data-level controls |
| Device enrollment commonly involved | Can support scenarios where full device management isn’t appropriate |
| Encryption/configuration/device restrictions | App protection/data controls |
A simple interview answer:
MDM manages the device; MAM focuses on protecting corporate data within supported applications.
5. What is Intune enrollment?
Enrollment is the process of registering a device with Intune so that Intune can manage it.
After enrollment, Intune can deliver applicable:
- Policies
- Configuration
- Applications
- Security settings
- Compliance requirements
For Windows, Microsoft supports several enrollment approaches including automatic enrollment, Windows Autopilot, BYOD enrollment and co-management with Configuration Manager.
6. What is Microsoft Entra ID’s role in Intune?
Microsoft Entra ID provides identity and device-related capabilities that integrate closely with Intune.
For example, a Windows device can be:
- Microsoft Entra joined
- Microsoft Entra hybrid joined
- Microsoft Entra registered
Intune then manages the device through MDM enrollment where applicable.
A simplified model is:
Microsoft Entra ID
↓
Identity + Device Identity
↓
Microsoft Intune
↓
Device Management
7. What is Microsoft Entra joined?
A Microsoft Entra joined Windows device is joined directly to Microsoft Entra ID rather than being joined to traditional on-premises Active Directory.
This model is commonly used for cloud-managed Windows devices.
Example:
Windows 11
↓
Microsoft Entra Join
↓
Intune Enrollment
↓
Cloud Management
It is particularly suitable for organizations moving toward cloud-native endpoint management.
8. What is Microsoft Entra hybrid joined?
Microsoft Entra hybrid join connects a Windows device to:
- On-premises Active Directory
- Microsoft Entra ID
The device remains joined to the organization’s traditional Active Directory while also having a Microsoft Entra device identity.
This is commonly encountered during:
- Cloud migration
- Intune adoption
- Co-management
- Hybrid identity deployments
9. What is Microsoft Entra registered?
Microsoft Entra registered devices are typically associated with users and are commonly used for scenarios such as:
- BYOD
- Personal devices
- Accessing organizational resources
Registration is different from a traditional Active Directory domain join or Microsoft Entra join.
10. What is automatic enrollment in Intune?
Automatic enrollment allows eligible devices to enroll into Intune automatically when the configured enrollment conditions are met.
For Windows, automatic enrollment can be used in scenarios including:
- Corporate devices
- BYOD
- Windows Autopilot
- Group Policy-based enrollment
- Co-management
Microsoft Entra and Intune enrollment configuration determine how the process works.
11. What is the difference between Microsoft Entra Join and Intune enrollment?
They are related but not identical.
Microsoft Entra Join
Establishes the device’s identity relationship with Microsoft Entra ID.
Intune Enrollment
Establishes device management through Intune.
A device can therefore have a Microsoft Entra identity and be enrolled into an MDM service.
For example:
Microsoft Entra Join
+
Intune Enrollment
↓
Cloud-managed Windows device
12. What is Windows Autopilot?
Windows Autopilot is a cloud-based Windows deployment and provisioning technology.
It is designed to simplify deployment of organization-owned Windows devices.
Instead of creating and maintaining a traditional custom Windows image, an organization can use the OEM-installed Windows operating system and configure the device during the out-of-box experience.
Microsoft’s current guidance describes Autopilot as an organization-owned Windows deployment option and notes that it requires automatic enrollment.
13. What are the major Windows Autopilot scenarios?
Important scenarios include:
User-driven
The user signs in with their organizational account and the device is configured for the user.
Self-deploying
The device can be provisioned with minimal user interaction, depending on the supported scenario and hardware.
Pre-provisioning
IT or a partner can prepare the device before handing it to the user.
Hybrid Microsoft Entra join
Autopilot can also be used with Microsoft Entra hybrid joined devices in supported configurations.
14. What is an Autopilot deployment profile?
An Autopilot deployment profile defines how Windows should behave during the Autopilot deployment process.
It can control aspects of the deployment experience such as:
- User-driven vs other supported deployment scenarios
- Microsoft Entra join configuration
- OOBE behavior
- User experience settings
- Device configuration options
The profile is assigned to appropriate device groups.
15. What is the Enrollment Status Page (ESP)?
The Enrollment Status Page is displayed during Windows provisioning and shows the progress of device configuration.
It can track deployment of:
- Applications
- Security policies
- Certificates
- Network configuration
- Other required configuration
The purpose is to ensure the device reaches the expected state before the user receives normal access to the desktop.
16. Why is ESP important during Autopilot?
Consider this scenario:
New laptop
↓
Autopilot
↓
User signs in
↓
Required applications
↓
Security configuration
↓
Device ready
Without appropriate ESP configuration, the user might receive access to the desktop before important applications or policies have completed.
ESP helps control this provisioning experience.
17. What happens if an application gets stuck during ESP?
First determine whether the application is:
- Required
- Assigned to the device/user
- Compatible with the deployment
- Installing successfully
- Reporting status correctly
Then investigate:
- Application assignment
- Detection rules
- Installation command
- Return code
- Dependency
- Network connectivity
- Intune Management Extension logs where applicable
- ESP logs
Do not immediately recreate the entire Autopilot deployment.
18. What is the Intune Company Portal?
Company Portal is the user-facing application and website used to provide access to organizational resources managed through Intune.
Depending on platform and configuration, users can:
- Install available applications
- View device information
- Start supported device actions
- Check compliance
- Resolve certain enrollment issues
It provides a self-service experience for users.
19. What is device check-in in Intune?
A managed device periodically communicates with Intune to retrieve and report management information.
During synchronization, the device can receive:
- Policy changes
- Application assignments
- Configuration updates
- Other management instructions
The normal synchronization interval varies by platform and scenario.
For Windows, Microsoft currently documents an approximately eight-hour default periodic check-in interval, while administrators can trigger an immediate sync.
20. How can you force an Intune device to synchronize?
For a Windows device, the user can initiate a sync from:
Settings → Accounts → Access work or school → Connected account → Info → Sync
The administrator can also initiate a sync from the Intune admin center where supported.
This is useful when troubleshooting:
“I assigned a policy five minutes ago, but the device hasn’t received it.”
21. A user says an Intune policy isn’t applying. What should you check first?
Do not immediately recreate the policy.
Check:
- Is the device enrolled?
- Is the user/device in the assigned group?
- Is the policy actually assigned?
- Is there an exclusion?
- Is the platform correct?
- Are applicability rules excluding the device?
- Is another policy conflicting?
- Has the device synchronized?
- Is the device in the expected management state?
- Is there an error in Intune device status?
This is the basic Intune troubleshooting sequence.
22. What are enrollment restrictions?
Enrollment restrictions control which devices and users can enroll into Intune and under what conditions.
They can help control:
- Platform availability
- Device types
- Enrollment scenarios
- Device limits
- Personally owned device enrollment
They are particularly important in large enterprises where unrestricted enrollment could create governance problems.
23. Why should organizations restrict personal-device enrollment?
Suppose an organization allows unrestricted BYOD enrollment.
Employees could potentially enroll:
Personal Laptop
Personal Tablet
Personal Phone
Old Device
Test Device
This can create:
- Security concerns
- Licensing issues
- Support overhead
- Privacy concerns
- Compliance complexity
A good design defines exactly which BYOD scenarios are allowed.
24. What is a device enrollment manager (DEM)?
A Device Enrollment Manager account is a specialized Intune account used for enrolling multiple devices in supported enrollment scenarios.
It is useful for certain shared-device or bulk enrollment scenarios.
However, DEM is not a replacement for Windows Autopilot.
Microsoft specifically documents that DEM accounts don’t apply to Windows Autopilot.
25. What is a device limit restriction?
A device limit controls how many devices a user can enroll.
For example:
Maximum devices = 5
If the user already has the maximum number of enrolled devices, another enrollment may fail.
During troubleshooting, therefore check:
- Existing devices
- Enrollment restrictions
- User’s device limit
- Stale device objects
26. What is device ownership in Intune?
Intune can distinguish between ownership types such as:
- Corporate
- Personal
Ownership can influence:
- Management behavior
- Enrollment restrictions
- Reporting
- Application deployment
- Compliance
- Administrative decisions
Correct ownership classification is therefore important.
27. What is a primary user?
The primary user identifies the main user associated with a managed device in Intune.
This is particularly useful for:
- Device ownership
- User support
- Reporting
- User-based application assignment
- Troubleshooting
However, the primary user should not automatically be treated as the only user who can use the device.
Shared devices can have different usage models.
A shared device is designed for multiple users rather than one dedicated user.
Examples:
- Reception computers
- Warehouse terminals
- Training-room computers
- Factory-floor devices
- Shared kiosks
These devices require different management considerations than a personal assigned laptop.
I would first identify the usage model.
For example:
Shared workstation
↓
Multiple users
↓
Minimal personalization
↓
Required applications
↓
Restricted configuration
↓
Centralized management
Then configure appropriate:
- Device configuration
- Security policies
- Application deployment
- User experience
- Sign-in behavior
- Compliance requirements
The exact configuration depends on the business requirement.
30. What are device categories in Intune?
Device categories allow organizations to classify devices according to organizational needs.
For example:
Finance
HR
IT
Warehouse
Kiosk
Executive
Categories can be useful for:
- Organization
- Reporting
- Group assignment strategies
- Administrative workflows
They should be used consistently rather than creating unnecessary categories.
31. What is an Intune scope tag?
Scope tags help control which Intune objects administrators can see and manage.
They are useful in delegated administration.
For example:
Central IT
↓
All devices
Regional IT
↓
Regional devices
Scope tags help separate administrative visibility and management responsibilities.
They solve different problems.
Scope tags
Control administrative visibility/scope.
Assignments
Determine which users or devices receive a policy, application or profile.
A simple way to remember:
Scope Tag
→ Who can manage/see it?
Assignment
→ Who receives it?
33. What is the Intune Management Extension?
The Intune Management Extension, or IME, is a Windows component used for certain Intune management capabilities, particularly Win32 application deployment and PowerShell script execution.
It is different from the core MDM channel.
Therefore, when troubleshooting a Win32 application or PowerShell deployment, you may need to investigate IME behavior and logs.
34. What is the difference between MDM and the Intune Management Extension?
MDM
Uses the Windows MDM channel and configuration service provider mechanisms for supported management settings.
Intune Management Extension
Provides additional capabilities such as:
- Win32 application deployment
- PowerShell scripts
- Certain advanced management tasks
Therefore:
Intune
├── MDM
└── Management Extension
They complement each other rather than being identical.
35. What is co-management?
Co-management allows an organization to manage Windows devices using both:
- Microsoft Configuration Manager
- Microsoft Intune
This is useful during gradual modernization from traditional endpoint management to cloud management.
For example:
Existing Environment
↓
Configuration Manager
+
Intune
↓
Gradual Cloud Transition
Microsoft documents co-management as one of the supported Windows enrollment approaches.
36. Why would an enterprise use co-management?
A large organization may have:
10,000 existing Windows devices
Immediately moving everything to Intune may not be practical.
Co-management allows the organization to gradually move workloads while continuing to use Configuration Manager where necessary.
Possible benefits include:
- Gradual migration
- Reduced migration risk
- Existing Configuration Manager investment
- Cloud-based management capabilities
- Flexible workload transition
37. What is Windows Autopilot device registration?
Before an organization can use Autopilot deployment for a device, the device must be registered in the organization’s Autopilot service.
The registration allows the organization to associate the device with its tenant and apply the appropriate deployment configuration.
After registration:
Device
↓
Autopilot registration
↓
Deployment profile
↓
Windows OOBE
↓
Enrollment
38. A new company laptop does not receive the Autopilot profile. What do you check?
Check in this order:
1. Is the device registered?
Verify the device appears in Windows Autopilot.
2. Is the correct deployment profile assigned?
Check the device/group assignment.
3. Is the device group membership correct?
Verify dynamic/static group membership.
4. Is there an exclusion?
Check profile exclusions.
5. Is the device connected to the Internet?
Autopilot requires network connectivity during provisioning.
6. Is the device running a supported Windows version?
7. Is the expected deployment scenario configured?
Do not immediately delete and recreate the device.
39. What happens if an Autopilot device is registered but the user sees normal Windows OOBE?
Investigate:
Autopilot registration
↓
Device identity
↓
Profile assignment
↓
Profile processing
↓
Network connectivity
↓
OOBE
Important checks include:
- Correct device registration
- Correct tenant
- Deployment profile assignment
- Assignment timing
- Internet connectivity
- Windows version
- Autopilot profile configuration
A registration record by itself does not guarantee that the desired profile has been applied.
40. What is Windows Autopilot pre-provisioning?
Pre-provisioning allows an administrator, OEM or partner to prepare a device before giving it to the end user.
The goal is to perform appropriate provisioning steps before the user receives the device.
Conceptually:
OEM / IT
↓
Autopilot Pre-provisioning
↓
Applications
Policies
Security
↓
User receives device
This can improve the user’s first-login experience.
41. What is the difference between Autopilot and traditional imaging?
Traditional imaging
Often involves:
Custom OS Image
↓
Deployment
↓
Drivers
↓
Applications
↓
Configuration
Autopilot
Uses the OEM Windows installation and cloud-based provisioning:
OEM Windows
↓
Autopilot
↓
Microsoft Entra
↓
Intune
↓
Policies + Applications
Autopilot therefore changes the provisioning model rather than simply being another imaging tool.
42. Can Windows Autopilot be used for BYOD?
Windows Autopilot is intended for organization-owned devices.
For personal/BYOD scenarios, Microsoft documents other Windows enrollment approaches such as automatic enrollment or user enrollment depending on the scenario.
This distinction is important in interviews.
43. A user enrolls a Windows device but it doesn’t appear correctly in Intune. What do you investigate?
I would check:
- Microsoft Entra device state
- Intune enrollment status
- User licensing
- MDM authority/configuration
- Enrollment restrictions
- Device limit
- User assignment
- Enrollment errors
- Device synchronization
- Whether the device is already managed by another MDM
The important point is to determine whether the failure is:
Identity
OR
Enrollment
OR
Management
rather than treating them as the same thing.
44. What happens if a device is already managed by another MDM provider?
A device generally cannot simply be fully managed by multiple competing MDM providers simultaneously.
For an organization moving to Intune, the existing MDM relationship may need to be removed or transitioned according to the supported migration process.
Microsoft’s Windows enrollment guidance specifically notes that devices managed by another MDM provider must be transitioned appropriately before being fully managed by Intune.
45. How would you troubleshoot an Intune enrollment failure?
Use a layered approach.
User
↓
License
↓
Enrollment configuration
↓
Microsoft Entra identity
↓
Enrollment restrictions
↓
Device state
↓
Network
↓
Intune service
↓
Device-side logs
Check:
- User license
- MDM scope
- Enrollment restrictions
- Device limit
- Platform restriction
- Microsoft Entra device state
- Existing MDM relationship
- Enrollment errors
- Device connectivity
- Intune service health
46. A user says “Intune is not syncing.” What should you ask?
First determine what “not syncing” means.
Ask:
- Are policies missing?
- Are applications missing?
- Is hardware inventory stale?
- Is compliance status stale?
- Is the device visible in Intune?
- When was the last check-in?
- Can the device manually sync?
- Are there enrollment errors?
This avoids troubleshooting the wrong component.
47. What is the difference between device check-in and compliance evaluation?
They are related but different.
Device check-in
The device communicates with Intune and can receive/report management information.
Compliance evaluation
Intune evaluates whether the device satisfies configured compliance requirements.
Conceptually:
Device Check-in
↓
Device reports state
↓
Intune evaluates compliance
↓
Compliant / Noncompliant
The compliance result can then be used by Microsoft Entra Conditional Access.
48. Why is Microsoft Entra Conditional Access important with Intune?
Intune can provide device compliance information to Microsoft Entra Conditional Access.
For example:
User
↓
Attempts access
↓
Conditional Access
↓
Check device state/compliance
↓
Allow or block according to policy
This allows organizations to make access decisions based partly on device security posture.
49. What happens when a device becomes noncompliant?
The exact behavior depends on the organization’s configured compliance actions and Conditional Access policies.
A typical flow is:
Device
↓
Compliance evaluation
↓
Noncompliant
↓
Notification / remediation
↓
Conditional Access may restrict access
Intune can apply configured actions for noncompliance, and Conditional Access can use the compliance state when integrated.
50. Design an Intune architecture for an organization with 5,000 Windows laptops.
I would design it around standardized cloud management rather than manually configuring individual devices.
A high-level architecture:
Microsoft Entra ID
|
|
Microsoft Intune
|
+----------------+----------------+
| | |
Enrollment Configuration Compliance
| | |
Autopilot Settings Catalog Compliance
| Security Policies
| | |
+----------------+----------------+
|
Managed Windows
Devices
|
Conditional Access
|
Microsoft 365 / Apps
I would establish:
Identity
- Microsoft Entra join where appropriate
- Hybrid join where required
- Appropriate user/device groups
Enrollment
- Automatic enrollment
- Windows Autopilot
- Enrollment restrictions
- Device ownership strategy
Management
- Configuration profiles
- Settings Catalog
- Security baselines
- Endpoint security
- Application deployment
Security
- Compliance policies
- Microsoft Entra Conditional Access
- Microsoft Defender integration where required
Operations
- Device inventory
- Monitoring
- Reporting
- Standard troubleshooting procedures
- Administrative delegation
Migration
For existing Configuration Manager environments:
- Evaluate co-management
- Define workload transition
- Pilot with representative users/devices
- Gradually expand deployment
Important Intune Troubleshooting Flow
When a Windows device is not behaving as expected:
1. Is the device enrolled?
↓
2. Is it correctly identified in Entra ID?
↓
3. Is it assigned to the required group?
↓
4. Is the policy/application assigned?
↓
5. Is there an exclusion?
↓
6. Is the device compliant?
↓
7. Has the device checked in?
↓
8. Did the device receive the policy?
↓
9. Did the local component process it?
↓
10. Is there a conflict or installation failure?
This troubleshooting sequence is much more useful in an interview than simply saying:
“I would force a sync.”
Quick Revision
| Topic | Key Point |
|---|---|
| Intune | Cloud endpoint management |
| MDM | Device-level management |
| MAM | Application/data protection |
| Entra Join | Cloud device identity |
| Hybrid Join | AD + Entra device identity |
| Entra Registered | Commonly used for BYOD scenarios |
| Enrollment | Registers device for management |
| Automatic Enrollment | Automatically enrolls eligible devices |
| Autopilot | Cloud-based Windows provisioning |
| ESP | Tracks provisioning/configuration progress |
| Company Portal | User self-service experience |
| DCR | Not applicable to Intune; this belongs to Azure Monitor |
| Device Ownership | Corporate/personal classification |
| Primary User | Main user associated with device |
| DEM | Specialized enrollment account |
| IME | Additional Windows management channel |
| Co-management | Configuration Manager + Intune |
| Compliance | Determines whether device meets requirements |
| Conditional Access | Can use device compliance as an access signal |
| Scope Tag | Administrative visibility/scope |
| Assignment | Determines who/what receives a policy |
Exam Answer Summary
1. What is Intune?
A cloud-based endpoint management platform for managing devices, applications and corporate data.
2. MDM vs MAM?
MDM manages devices; MAM focuses on application/data protection.
3. Entra Join vs Intune Enrollment?
Entra Join establishes the device identity relationship with Microsoft Entra ID; Intune enrollment establishes management through Intune.
4. What is Autopilot?
A cloud-based Windows provisioning technology that uses the OEM Windows installation and configures the device through the out-of-box experience.
5. What is ESP?
Enrollment Status Page shows and controls the progress of device provisioning before normal desktop access.
6. What is co-management?
Management of Windows devices using both Configuration Manager and Intune during a transition or hybrid management strategy.
7. What is a scope tag?
A mechanism for controlling administrative visibility and scope in Intune.
8. What is an assignment?
An assignment determines which users or devices receive a policy, profile, application or other configuration.
Senior Interview Tip
For an Intune interview, don’t describe Intune as simply:
“A cloud version of Group Policy.”
That answer is incomplete.
A better senior-level explanation is:
“Intune is a cloud endpoint-management platform that uses multiple management mechanisms, including Windows MDM and the Intune Management Extension, and integrates with Microsoft Entra ID, Conditional Access, Microsoft Defender and other Microsoft security services. For Windows, I would design enrollment using automatic enrollment and Autopilot where appropriate, apply configuration and security policies through appropriate Intune policy types, evaluate device compliance, and use Conditional Access to control access based on the device’s security state.”
That demonstrates understanding of the architecture, not just the portal.
Next Part
Continue the Microsoft Intune Interview Series
Complete Series: [Microsoft Intune Interview Questions & Answers – Complete Series] | Next Part →: [Part 2: Configuration Profiles, Security Baselines & Troubleshooting]
Part 2 – Microsoft Intune Configuration Profiles, Settings Catalog, Security Baselines & Policy Troubleshooting
The next part will focus specifically on:
- Configuration profiles
- Settings Catalog
- Administrative Templates
- Security Baselines
- Policy assignment
- User vs device targeting
- Filters
- Applicability rules
- Policy conflicts
- Policy precedence
- Windows CSP concepts
- Policy processing
- Sync and refresh
- Policy troubleshooting
- Real-world configuration scenarios
Official Microsoft Intune Documentation
For the latest Microsoft Intune documentation, supported capabilities and current configuration guidance, refer to Microsoft Learn.
Microsoft Intune Documentation:
https://learn.microsoft.com/en-us/intune/
Microsoft’s documentation is the authoritative source for current Intune capabilities because enrollment methods, supported platforms, policies and management features can change over time. (Microsoft Learn)
