MD-102 Prepare infrastructure for devices Practice Question
A user has an Android Enterprise fully managed device. The device is enrolled in Microsoft Intune and all policies are applied. However, the user cannot install a required app from the managed Play Store. The app appears in the company portal but fails to install. What should you check first?
⚠ Common exam trap
MD-102 often tests the managed Google Play approval process, confusing candidates with other Android Enterprise concepts like enrollment tokens or unmanaged store.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the app has been approved in the managed Google Play store.
For Android Enterprise fully managed devices, apps must be approved in the managed Google Play store before they can be installed via Intune. If an app appears in the Company Portal but fails to install, the most likely cause is that it hasn't been approved in the managed Play Store. This is a common configuration step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ensure that the device has a policy to allow installation of unapproved apps.
Why it's wrong here
Fully managed devices only install apps from the managed Play Store, so a policy permitting unapproved app installation does not govern this failure and addresses sideloading instead. That setting would be relevant when allowing users to install APKs outside the managed store, not for a managed Play Store deployment that is already approved.
- ✗
Check if the device's enrollment token is still valid.
Why it's wrong here
Enrolment tokens are consumed at enrolment; the device is already enrolled and receiving policies, so token validity cannot block an app install. Checking tokens would be correct when a new device fails to enrol or when a bulk enrolment token has expired before provisioning.
- ✗
Check if the app is available in the unmanaged Play Store.
Why it's wrong here
Fully managed devices cannot use the unmanaged Play Store, so availability there is irrelevant to this failure. Verifying unmanaged store availability would be the correct check for personally owned work profile devices, where apps come from the public Play Store rather than the managed one.
- ✓
Verify that the app has been approved in the managed Google Play store.
Why this is correct
Approval in managed Google Play is mandatory before an Android Enterprise fully managed device can install any app, even when it appears in the Company Portal. Unapproved apps remain unavailable to Intune, so the install silently fails. Checking approval status directly addresses the managed Play Store constraint in the stem.
Go deeper
Related to this question
Learn chapter
Configuring Compliance Policies
Key term
Company Portal
Company Portal is a Microsoft app that gives employees a secure, self-service way to enroll devices, access company apps, and manage work resources from any device.
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.