Courseiva
Protect devices →easyMultiple Choice

MD-102 Protect devices Practice Question

A company uses Microsoft Intune to manage Windows 11 devices. They want to ensure that only devices with a TPM 2.0 and Secure Boot enabled can access corporate resources in Microsoft Entra ID. What should they configure?

⚠ Common exam trap

A common mix-up: candidates confuse provisioning-time enforcement (Autopilot) with runtime compliance enforcement (Conditional Access + compliance policy), mistakenly thinking Autopilot can block access after the device is in use.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Conditional Access policy that requires device compliance and a device compliance policy that checks TPM 2.0 and Secure Boot

Conditional Access policies in Microsoft Entra ID can require devices to be marked as compliant before granting access to corporate resources. A device compliance policy in Intune can be configured to check for TPM 2.0 and Secure Boot status on Windows 11 devices. Only when both conditions are met will the device be considered compliant, and the Conditional Access policy will enforce that compliance requirement, effectively blocking non-compliant devices from accessing corporate resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure Windows Hello for Business in Intune

    Why it's wrong here

    Windows Hello for Business governs credential issuance and sign-in method on the device; it does not read TPM version or Secure Boot state to authorise resource access. It is tempting because it is TPM-backed, but that binding protects keys, not conditional access, which needs device compliance or a conditional access policy.

  • ✗

    Deploy an attack surface reduction rule in Microsoft Defender XDR

    Why it's wrong here

    Attack surface reduction rules block behaviours such as Office macros spawning processes; they do not evaluate TPM 2.0 or Secure Boot state, so device access to Microsoft Entra ID resources is unaffected. ASR suits malware and exploit prevention on enrolled endpoints, not conditional access based on hardware attestation.

  • ✗

    Use Windows Autopilot to enforce TPM and Secure Boot during provisioning

    Why it's wrong here

    Autopilot enforces TPM and Secure Boot only while provisioning a device; it does not evaluate those attributes at sign-in, so an already-provisioned or non-Autopilot device still reaches resources. Autopilot suits zero-touch deployment, whereas ongoing access control requires a Microsoft Entra ID conditional access policy.

  • ✓

    Create a Conditional Access policy that requires device compliance and a device compliance policy that checks TPM 2.0 and Secure Boot

    Why this is correct

    Conditional Access enforces the access decision in Microsoft Entra ID, while the compliance policy evaluates TPM 2.0 and Secure Boot via device health attestation. Combining both satisfies the requirement that only compliant devices reach corporate resources.

About these practice questions

One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.