Be able to build a compliance policy, link it to Conditional Access, and assign configuration or security baseline profiles to the right groups. The single most important thing: know which policy type enforces a setting versus which one only reports device state.
Start practicing
Protect devices — choose a session length
Free · No account required
Domain overview
Domain 3 of MD-102 covers keeping endpoints secure with Intune: compliance policies, Conditional Access, device restrictions and configuration profiles, encryption with BitLocker and FileVault, Windows Defender and Attack Surface Reduction, and Defender for Endpoint onboarding. Questions are scenario-based, asking you to pick the setting, policy type, or OMA-URI that produces a described outcome.
Exam objectives
Compliance policies defining minimum OS version, encryption, and jailbreak or rooted detection
Conditional Access requiring compliant or Microsoft Entra hybrid joined devices
Configuration profiles and custom OMA-URI settings for device restrictions and security baselines
BitLocker, FileVault, and Windows Defender Firewall, ASR, and Defender for Endpoint onboarding
Confusing compliance policy settings with configuration profile settings, so the device is configured but never marked compliant.
Forgetting that Conditional Access needs a separate policy; a compliance policy alone does not block access to resources.
Mixing up Microsoft Entra registered, joined, and hybrid joined states, which changes which device controls and policies apply.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A user reports that their Windows 11 device is not receiving compliance policies from Microsoft Intune. The device shows as 'Not evaluated' in the Microsoft Intune admin center. Which step should you take first to resolve the issue?
2Your organization uses Microsoft Entra ID joined devices with Windows 10. You need to ensure that only compliant devices can access corporate email in Microsoft Outlook for Windows. Which integration should you enable?
3Your organization uses Windows Autopilot for device deployment. After a device completes the user-driven deployment, it appears in Microsoft Entra ID as 'Azure AD registered' instead of 'Azure AD joined'. What should you modify to ensure the device is joined?
4You are investigating a malware incident on a Windows 10 device managed by Microsoft Intune and protected by Microsoft Defender for Endpoint. Which log should you analyze to determine the initial infection vector?
5Refer to the exhibit. You configure this Enrollment Status Page (ESP) policy for Windows Autopilot deployments. During a deployment, a device fails to install a required app. What happens?
6Your organization uses Microsoft Intune to manage Windows 10 devices. You need to deploy a security baseline that enforces BitLocker encryption and Windows Defender Antivirus settings. What is the recommended approach?
7You need to ensure that only compliant devices can access Microsoft 365 resources. You create a Conditional Access policy in Microsoft Entra ID. Which condition should you use?
8You need to wipe a lost corporate-owned iOS device that is enrolled in Intune. Which action should you perform?
9Refer to the exhibit. You are deploying a custom OMA-URI policy to Windows 10 devices. What is the effect of this policy?
10A company uses Microsoft Intune to manage Windows 11 devices. They want to ensure that only devices with a TPM 2.0 and Secure Boot enabled can access corporate resources in Microsoft Entra ID. What should they configure?
11A company uses Microsoft Defender for Endpoint to manage endpoint security. They observe that some devices are not reporting vulnerability data to Microsoft Defender XDR. Which component is most likely misconfigured?
12An organization wants to enforce encryption on all Windows 10/11 devices using Intune. Which policy type should they use?
13A company uses Intune to manage macOS devices. They need to deploy a custom configuration profile that enforces FileVault encryption. What is the recommended approach?
14Your organization uses Windows Defender Application Control (WDAC) to allow only approved apps. After deploying a WDAC policy via Intune, some users report that a critical line-of-business app is blocked. How should you troubleshoot?
15A company wants to prevent users from copying corporate data from managed Microsoft 365 apps to personal apps on iOS devices. What should they configure?
16Which TWO actions should you take to ensure that only healthy Windows 10/11 devices can access Microsoft 365 services? (Choose two.)
17A user reports that their iOS device is not receiving email on their work account. The device is enrolled in Intune. You verify that the Exchange ActiveSync profile is assigned correctly. What should you check next?
18You manage Windows 10 devices with Intune. You need to ensure that only approved apps can run on corporate devices. You configure AppLocker via a custom OMA-URI. However, users can still run unapproved apps. What is the most likely reason?
19Your organization uses Microsoft Defender for Cloud Apps (part of Microsoft Defender XDR). You need to detect when users access cloud apps from unauthorized locations. Which log source should you integrate to get location information?
20Your company uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that work apps are sandboxed from personal apps. Which enrollment type should you use?
21You need to configure Microsoft Defender for Endpoint on macOS devices. Which THREE components must be installed?
22Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that corporate data is separated from personal data on the device. Which management approach should you use?
23Your organization uses Microsoft Defender for Cloud Apps. You need to configure a policy that automatically blocks downloads of sensitive data from SharePoint Online to unmanaged devices. Which policy type should you use?
24Which TWO actions can you perform using Microsoft Intune to protect devices from malware?
25Refer to the exhibit. You deploy this endpoint protection configuration to a Windows 10 device. A user reports that they cannot connect to the device via RDP. What is the most likely cause?
26You manage Windows 10 devices with Microsoft Intune. A user reports that a device has a red shield icon in the Windows Security Center, indicating tamper protection is off. You need to re-enable tamper protection on the device using Intune. Which profile type should you configure?
27Your organization uses Windows Autopilot and Microsoft Intune. You need to ensure that during the Autopilot deployment, the device automatically installs a set of required applications (Microsoft 365 Apps, company portal, and a line-of-business app) before the user can access the desktop. Which configuration should you use?
28You have a Windows 10 device that is managed by Intune and enrolled in Microsoft Defender for Endpoint. The device is reporting a high number of false positive detections from Microsoft Defender Antivirus. You need to configure an exclusion for a specific folder path to reduce false positives. Where should you configure the exclusion?
29You are reviewing an Intune endpoint protection profile for Windows 10. The exhibit shows a JSON snippet of the configuration. A user reports that a device detected malware with moderate severity, but the action taken was 'quarantine'. However, the desired action is 'clean'. Which setting should you modify?
30You are troubleshooting a Windows 10 device that is showing as non-compliant in Intune. The exhibit shows the PowerShell output from the Microsoft Graph API. Based on the output, what is the most likely reason for the non-compliance?
31You are reviewing a custom device configuration profile in Intune. The exhibit shows an OMA-URI setting. What is the purpose of this setting?
32You need to ensure that devices enrolled in Microsoft Intune automatically receive Windows quality updates as soon as they are released. Which update ring setting should you configure?
33You need to deploy a Microsoft 365 Apps for enterprise configuration to devices managed by Intune. Which policy type should you use?
34Refer to the exhibit. You deploy this compliance policy to Windows 10 devices. A device reports as compliant, but you suspect it may have a weak password policy because the password type is 'deviceDefault'. What is the effect of 'deviceDefault' on the password requirement?
35Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that corporate data in Microsoft Outlook is protected even if the device is not enrolled in MDM. Which policy should you deploy?
36You have a hybrid Microsoft Entra ID joined Windows 10 device that is co-managed with Configuration Manager and Intune. You want Intune to manage Windows Update for Business settings. Which slider setting should you configure in Configuration Manager?
37You configure a Windows 10 device compliance policy in Intune that requires 'Firewall' to be enabled. The device has Windows Defender Firewall enabled, but the device reports as non-compliant. You verify that the firewall is active. What is the most likely cause?
38Refer to the exhibit. You deploy this custom OMA-URI policy to Windows 10 devices. What is the expected outcome?
39Refer to the exhibit. You run a PowerShell command to check the assignment status of device configuration profiles. The 'BitLocker Policy' shows 'Pending'. What does 'Pending' indicate?
40Your organization uses Microsoft Intune to manage Windows 11 devices. You need to ensure that only devices with a Trusted Platform Module (TPM) version 2.0 and Secure Boot enabled can access corporate email. What should you configure?
41Your organization wants to deploy Windows Update for Business policies using Microsoft Intune to Windows 10 devices. Which policy type should you use?
42You need to ensure that only authorized users can enroll devices in Microsoft Intune. Which setting should you configure?
43Which THREE of the following are features of Microsoft Defender for Endpoint that help protect devices?
44Your organization uses Microsoft Intune to manage Windows 11 devices. You need to configure a device compliance policy that requires devices to run Windows version 22H2 or later. When you create the policy, which option must you select for the OS version requirement?
45Your company deploys Microsoft Defender for Endpoint (Defender XDR) to all Windows devices. You need to create a custom detection rule that triggers an alert when a specific PowerShell script is executed on any device. Which action should you take in the Microsoft 365 Defender portal?
46You manage devices with Microsoft Intune. You need to deploy a Windows 10 feature update to a pilot group of devices. Which profile type should you use?
47Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to ensure that all devices have a passcode of at least 6 characters and that devices are updated to the latest iOS version. You create a compliance policy. After assigning the policy, some devices are marked as non-compliant even though they have a passcode. What is the most likely cause?
48You need to enroll a Windows 11 device into Microsoft Intune using a work or school account. The device is already joined to Microsoft Entra ID. What is the simplest enrollment method?
49Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to deploy a managed Google Play app to work profile devices. After deploying, users report that the app is not available in the work profile. What is the most likely cause?
50Your company uses Microsoft Defender for Endpoint (Defender XDR). You need to configure an automated investigation and remediation (AIR) rule that automatically quarantines a file when a specific alert is triggered. Which action should you take?
51You are configuring Microsoft Intune for Windows 10 devices. Which two settings can you enforce using a device restrictions profile? (Select TWO.)
52You review the compliance policy JSON for Windows 10 devices. A device running Windows 10 version 22H2 (build 22621.0) with a numeric-only password of 10 characters, BitLocker enabled, firewall enabled, and Microsoft Defender running reports as non-compliant. What is the most likely reason?
53Your organization, Fabrikam, uses Microsoft Intune to manage iOS/iPadOS and Android devices. You need to implement a solution that ensures company email can only be accessed from the Outlook mobile app, and that data from the Outlook app cannot be copied to personal apps. You also need to ensure that when a user leaves the company, the corporate data in Outlook is removed without affecting personal data. You plan to use app protection policies (MAM). The devices are not enrolled in Intune (unmanaged). You configure the app protection policies for Outlook on iOS and Android. However, users report that they can still copy email content to personal apps. What should you check?
54An IT administrator needs to ensure that iOS devices enrolled in Intune require a PIN of at least 6 digits. Where should the administrator configure this setting?
55An administrator needs to ensure that only devices with a specific manufacturer are allowed to enroll in Intune. Which setting should the administrator configure?
56A hospital uses Intune to manage Windows 10 devices used by doctors. The devices should automatically install critical updates from Windows Update for Business. Which type of policy should the administrator create?
57An organization uses Microsoft Defender for Cloud Apps to monitor cloud app usage. The security team wants to automatically apply an Intune app protection policy (APP) when a user accesses a risky app from an unmanaged device. What should the administrator use?
58A company wants to prevent corporate data from being copied from managed apps to personal apps on iOS devices. Which Intune policy should the administrator configure?
59An Intune administrator needs to ensure that Windows 10 devices are compliant with security requirements. Which TWO options are valid compliance settings for Windows 10?
60Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that devices are compliant with a new security policy that requires Windows Defender Antivirus to be enabled and up-to-date. You create a device compliance policy with the setting 'Require' for Windows Defender Antivirus. After assigning the policy, you see that 90% of devices are compliant. The remaining 10% show 'Not evaluated'. You check the devices and find that they are online, enrolled, and have Windows Defender Antivirus enabled. What is the most likely reason for the 'Not evaluated' status?
61Your organization uses Microsoft Entra ID joined devices and Microsoft Intune for mobile device management. A user reports that their device is not receiving compliance policies. The device shows as 'Compliant' in Intune but the Conditional Access policy still blocks access. What should you verify first?
62Refer to the exhibit. The JSON shows a compliance policy for Windows 10 devices. Devices that do not meet the policy are marked as non-compliant. Which diagnostic step would you take to identify why a specific device is non-compliant despite having BitLocker enabled?
63Your company has 500 Windows 10 devices that are Hybrid Azure AD joined and managed by Microsoft Intune. You need to deploy a new line-of-business (LOB) app to all devices. The app is packaged as a .msi file. You create a new app in Intune and assign it to a device group containing all devices. After 24 hours, some devices report the app as 'Installed' but others show 'Failed'. You verify that the devices are online and have network connectivity. What should you do next to resolve the installation failures?
64Your organization uses Microsoft Intune to manage iOS and Android devices. You have a compliance policy that requires a minimum OS version: iOS 16.0 and Android 12.0. You also have a Conditional Access policy that requires compliant devices. Several users report that they cannot access corporate email on their personal Android devices. The devices are Android 11.0. You need to allow these users to access email while ensuring that corporate data is protected. What should you do?
65Your organization uses Microsoft Intune to manage Android devices. You need to ensure that corporate data on these devices is protected in case the device is lost or stolen. You configure a compliance policy that requires device encryption and a device lock screen. However, you also want to be able to selectively wipe corporate data without wiping personal data. What should you do?
66Your organization uses Microsoft Intune to manage devices. You have a Windows 10 device that is co-managed with Configuration Manager. You need to configure a policy that requires BitLocker encryption. You create a BitLocker policy in Intune and assign it to the device. After 24 hours, BitLocker is not enabled on the device. You verify that the device is online and the policy is assigned. What is the most likely cause?
67Your organization uses Microsoft Intune to manage Windows 11 devices. You need to configure a device compliance policy that automatically marks a device as noncompliant if it has not checked in with Intune for more than 30 days. Which compliance setting should you configure?
68You manage Windows 11 devices enrolled in Microsoft Intune. Security requires that devices with unsupported antivirus signatures be blocked from accessing Microsoft 365 resources. You create a compliance policy that sets the Microsoft Defender Antivirus requirement to 'Require' and the 'Antivirus signature age' to 3 days. A device reports an antivirus signature age of 5 days. What is the resulting device state?
69You are configuring a Microsoft Intune compliance policy for Windows 11 devices. You need to ensure that devices with BitLocker not enabled are marked noncompliant. Which setting should you configure in the compliance policy?
70Your organization uses Microsoft Intune to manage Windows 10 devices. You need to create a compliance policy that requires devices to have a firewall enabled. Which setting should you configure?
71You are an endpoint administrator for a company that uses Microsoft Intune to manage Windows 11 devices. You have a device compliance policy that requires BitLocker Drive Encryption to be enabled on the OS drive. A user reports that their device is marked as non-compliant, even though they have BitLocker enabled and the drive is encrypted. You check the device and see that the BitLocker protection status is 'Protection Off' in the BitLocker control panel. The user has not set up a PIN. You need to ensure the device is compliant. What should you do?
72You have a Microsoft 365 subscription that includes Microsoft Intune. You have 100 Windows 11 devices enrolled in Intune. You need to ensure that BitLocker recovery keys are automatically escrowed to Microsoft Entra ID when BitLocker is enabled. What should you configure?
73Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to configure a compliance policy that enforces encryption and firewall settings. Which two settings should you configure in the compliance policy? (Choose two.)
74Your organization uses Microsoft Intune to manage Windows 11 devices. The security team requires that BitLocker recovery keys be automatically escrowed to Microsoft Entra ID before a device is marked compliant. You need to configure a compliance policy setting that enforces this. Which setting should you configure?
75You manage Windows 11 devices with Microsoft Intune. You need to configure a policy that will automatically lock the screen after 5 minutes of inactivity and require a password to unlock. Which policy type should you use?
76You manage Windows 11 devices with Microsoft Intune. Security requires that when a device is marked as noncompliant, access to Microsoft 365 services is blocked within 5 minutes, even if the user is already signed in. You configure a Conditional Access policy that requires a compliant device. What else must you configure to achieve this near-real-time enforcement?
77You manage 500 Windows 11 devices with Microsoft Intune. A security policy requires that all devices run Microsoft Defender Antivirus with real-time protection enabled. You configure a Windows 10 and later antivirus policy in Intune and assign it to all devices. Several devices report that real-time protection is disabled. You need to ensure that real-time protection cannot be disabled by local administrators. What should you do?
78You use Microsoft Intune to manage Windows 11 devices. You need to configure a device compliance policy that automatically marks devices as noncompliant if they do not have a specific antivirus signature version installed. The signature version is updated daily. Which compliance setting should you configure?
79You manage a hybrid Azure AD joined Windows 11 device with Microsoft Intune. You need to configure a device compliance policy that requires BitLocker drive encryption and Secure Boot to be enabled. Which two settings must you configure in the compliance policy? (Choose two.)
80You are deploying a new line-of-business app to 500 Windows 11 devices using Microsoft Intune. The app requires a specific PowerShell script to run after installation to configure registry settings. You need to ensure the script runs only after the app is successfully installed and that it does not require user interaction. What should you do?
81Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that devices cannot access corporate email if they are rooted. What should you configure?
82You are deploying Microsoft Defender for Endpoint to 200 Windows 10 devices managed by Microsoft Intune. You want to onboard the devices to Defender for Endpoint using the least administrative effort. What should you do?
83You manage a set of Windows 11 devices with Microsoft Intune. You need to configure attack surface reduction (ASR) rules to block Office applications from creating child processes. You want to ensure the rules are enforced and cannot be bypassed by users. Which Intune profile type should you use?
84You manage a fleet of Windows 10 devices with Microsoft Intune. You need to ensure that when a device is marked as noncompliant, it loses access to corporate email and Teams within 15 minutes. You have already configured a compliance policy and assigned it to all users. What should you do next to meet the requirement?
85Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to implement a policy that requires devices to meet specific hardware and software conditions before they can access corporate email. The policy must evaluate the device's encryption status, OS version, and whether it has a firewall enabled. What should you create?
86Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to prevent users from installing apps from unknown sources on their personally-owned work profile devices. Which configuration profile type should you use?
87Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to ensure that BitLocker Drive Encryption is enabled on all devices and that the recovery keys are escrowed to Azure Active Directory (Azure AD). Which policy type should you use?
88You use Microsoft Intune to manage Windows 10 devices. You need to create a compliance policy that requires devices to have a minimum OS version of 10.0.19044. You configure the setting 'Minimum OS version' to '10.0.19044'. Which additional setting must you configure to ensure that devices running a higher version, such as 10.0.19045, are also considered compliant?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to build a compliance policy, link it to Conditional Access, and assign configuration or security baseline profiles to the right groups. The single most important thing: know which policy type enforces a setting versus which one only reports device state.
The Courseiva MD-102 question bank contains 88 questions in the Protect devices domain, covering the 18% of the exam attributed to this domain in the official Microsoft blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Protect devices domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included