mediumMultiple ChoiceObjective-mapped
MD-102 Practice Question: A company uses Microsoft Intune to manage Windows…
A company uses Microsoft Intune to manage Windows 10 devices. They need to ensure that only devices with BitLocker enabled can access corporate email via Exchange Online. Which configuration should the administrator use to enforce this requirement?
⚠ Common exam trap
Many exam-takers confuse Device Compliance policies (which only report status) with Conditional Access policies (which enforce access control), leading them to pick Option A, thinking compliance alone blocks access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy that requires device compliance and assign it to Exchange Online.
A Conditional Access policy in Azure AD can require that devices accessing Exchange Online be marked as compliant in Intune. By combining a Device Compliance policy that requires encryption (BitLocker) with a Conditional Access policy targeting Exchange Online, only compliant devices with BitLocker enabled will be granted access to corporate email.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a Device Compliance policy for Windows 10 with the 'Require encryption of data storage on device' setting enabled.
Why it's wrong here
Compliance policies mark devices as non-compliant but do not enforce access control without Conditional Access.
- ✓
Create a Conditional Access policy that requires device compliance and assign it to Exchange Online.
Why this is correct
Conditional Access can enforce access based on compliance, which includes BitLocker status.
- ✗
Create an App Protection policy for the Outlook mobile app that requires device encryption.
Why it's wrong here
App Protection policies apply to apps, not to the device itself, and do not enforce BitLocker.
- ✗
Configure Windows Defender Firewall to block non-BitLocker encrypted devices.
Why it's wrong here
Firewall does not enforce encryption requirements.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
Key term
Windows 10
Windows 10 is a personal computer operating system developed by Microsoft that combines the familiarity of Windows 7 with the modern features of Windows 8, designed to run on a wide range of devices from desktops to tablets.
About these practice questions
Courseiva writes every MD-102 question from scratch — 942 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.