You're the systems administrator for an international sports equipment retail company. The company requires that the Windows 11 laptops for employees be replaced with new Windows 11 laptops every 3 years.In addition, the company requires the following:When the employees log into their new laptops, all the existing user and application settings need to be in place.There must be a separation of corporate and employee data.Data must be automatically encrypted with Azure Rights Management.Which of the following features would BEST meet the company's requirements?answerWindows Information Protection (WIP)Microsoft IntuneEnterprise State RoamingAzure Active Directory single sign-on (SSO)
Question
You're the systems administrator for an international sports equipment retail company. The company requires that the Windows 11 laptops for employees be replaced with new Windows 11 laptops every 3 years.In addition, the company requires the following:When the employees log into their new laptops, all the existing user and application settings need to be in place.There must be a separation of corporate and employee data.Data must be automatically encrypted with Azure Rights Management.Which of the following features would BEST meet the company's requirements?answerWindows Information Protection (WIP)Microsoft IntuneEnterprise State RoamingAzure Active Directory single sign-on (SSO)
Solution
The best feature to meet the company's requirements would be a combination of Microsoft Intune and Enterprise State Roaming.
Microsoft Intune is a cloud-based service that focuses on mobile device management (MDM) and mobile application management (MAM). It can help control how your organization's devices are used, including mobile phones, tablets, and laptops. It can also provide a way to manage the mobile apps your workforce uses.
Enterprise State Roaming provides a user experience across devices, enabling users to roam their settings and modern app data across all their Windows devices. This feature is beneficial for the company's requirement that all existing user and application settings need to be in place when employees log into their new laptops.
Windows Information Protection (WIP) could be used to separate corporate and employee data, but it doesn't cover all the requirements.
Azure Active Directory single sign-on (SSO) could be used to simplify user access, but it doesn't cover all the requirements either.
Azure Rights Management is now Azure Information Protection, which is more about classifying and protecting documents and emails rather than encrypting data at rest on the device itself.
So, the combination of Microsoft Intune and Enterprise State Roaming would be the best fit for the company's requirements.
Similar Questions
Listen to exam instructionsYou're the systems administrator for an international trading company that uses Azure Active Directory (AD) and Microsoft Intune to manage their mobile devices. All company-owned mobile devices are registered in Azure AD and enrolled in Microsoft Intune.Many company-owned laptops are currently running Windows 10 and are enrolled in Microsoft Intune. You want to identify which of these laptops can be upgraded to Windows 11.SOLUTION: You create a device compliance policy and assign the policy to the laptops. After 24 hours, you view the device compliance report in Intune.DragYesNoDropDoes this solution help you identify which laptops can be upgraded?
You're the systems administrator for an international sports equipment retail company that uses Azure Active Directory (AD) and Microsoft Intune to manage their mobile devices. All company-owned Windows 11 mobile devices are registered in Azure AD and enrolled in Microsoft Intune.You decide that you want to create an Intune conditional access policy that:Applies the policy to the Office 365, Microsoft Teams, and SharePoint cloud apps.Assigns the policy to Windows platforms.Requires the Windows 11 devices to be marked as Compliant.To properly configure this Intune conditional access policy, you need to perform several tasks. From the list of tasks on the left, drag the tasks to the right in the proper order for creating the policy. (Not all listed tasks are part of creating the policy.)Give the policy a name.Enable the policy.Send an email to the users.Assign users and user groups.Select cloud apps or user actions.Grant or block access based on controls.Select conditions.Set up network fencing.Determine the OS version.move rightmove left
Which of the following can help you ensure that that only authorized users are accessing your organization's data and applications, and that those users are doing so from secure devices and locations?answerMicrosoft Intune user listsMicrosoft Intune conditional access policiesMicrosoft Intune AutoPilotMicrosoft Intune Windows Update for Business
You want to use a Microsoft tool to provide remote assistance on Windows 11 laptops assigned to your employees. You also want limit the administrative tasks that Level 1 Help Desk support staff can perform on a remotely-connected laptop.You have Intune installed and are using Azure Active Directory to manage users and accounts.Which of the following tools would BEST meet your remote connection requirements?answerQuick AssistRemote HelpRemote AssistanceRemote Desktop
Listen to exam instructionsAll your company-owned Windows laptops are currently enrolled in Intune for management purposes.One of your employees is on long-term leave and you have assigned the employee's laptop to someone else. You want the new laptop owner to be assigned as the primary user the first time they log in.Which of the following Intune security features could you easily use remotely to meet your logon requirement?answerAutopilot resetRemote wipeRemote lockCustom policy
Upgrade your grade with Knowee
Get personalized homework help. Review tough concepts in more detail, or go deeper into your topic by exploring other relevant questions.