In a Microsoft 365 tenant using Intune Suite you need to remove User1 from the local Administrators group on all enrolled Windows 11 devices. Which policy type should you configure?
Choose an answer
Tap an option to check your answer.
Correct answer: An account protection policy.
Why this is the answer
An account protection policy is the correct choice because it allows you to configure local user group membership on Windows devices, including removing specific users from the local Administrators group. This policy type is part of Endpoint Security in Intune and is designed for managing security-related settings for user accounts. A device compliance policy defines conditions devices must meet to be considered compliant, but it doesn't directly modify local group membership. An app configuration policy is used to customize settings within applications, not to manage local user groups on the operating system.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed