Courseiva

MD-102 Manage and maintain devices Practice Question

A user's iOS device is enrolled in Microsoft Intune and is compliant. However, the user cannot access corporate email in the Outlook mobile app. The app displays an error that the device is not compliant. What is the most likely cause?

⚠ Common exam trap

Many exam-takers assume the error means the device is not enrolled or that the app is missing, but the question explicitly states the device is enrolled and compliant, so the most likely cause is a policy change that retroactively affects compliance status.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A compliance policy was updated requiring a newer OS version or additional security settings.

Intune compliance policies are evaluated in real time when a user attempts to access corporate resources. If an administrator updates a policy to require a newer iOS version or additional security settings (e.g., passcode complexity, encryption), the device may become non-compliant even if it was previously compliant. The Outlook app checks device compliance via the Intune SDK and will block access if the device no longer meets the policy requirements, displaying the 'device not compliant' error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user's Intune license has expired.

    Why it's wrong here

    An expired Intune licence would prevent the device from checking in and reporting compliance at all, yet the stem says the device is enrolled and compliant, so licensing is not the failing component. It is tempting because licence problems commonly cause policy failures, and would be correct if the user had no valid Intune or Microsoft Entra ID licence assigned.

  • ✗

    The Outlook app is not installed on the device.

    Why it's wrong here

    The error explicitly reports a compliance failure, and Outlook would not launch far enough to evaluate compliance if the app were absent; installation state is unrelated to the device compliance signal. It is tempting because missing apps do block access under some app protection policies, and would be correct if the user simply had no Outlook client installed.

  • ✓

    A compliance policy was updated requiring a newer OS version or additional security settings.

    Why this is correct

    Intune evaluates compliance on device check-in, so a policy change adding a minimum OS version or stronger security settings marks the previously compliant iOS device non-compliant, blocking Outlook mobile access via conditional access until the device meets the new requirements.

  • ✗

    The device is not enrolled in Intune.

    Why it's wrong here

    The stem states the device is already enrolled in Intune, so non-enrolment contradicts the given facts and cannot explain the compliance error. It is tempting because unenrolled devices are a common cause of Conditional Access blocks, and would be correct if the device had never been enrolled or had been removed from the tenant.

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.