MD-102 Protect devices Practice Question
An IT administrator needs to ensure that iOS devices enrolled in Intune require a PIN of at least 6 digits. Where should the administrator configure this setting?
⚠ Common exam trap
MD-102 often tests the difference between device compliance policies (device-wide settings) and app protection policies (app-level settings), so candidates may incorrectly choose app protection policy for device PIN requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Device compliance policy for iOS
Device compliance policies in Intune define the rules and settings that devices must meet to be considered compliant, including password requirements such as minimum PIN length. For iOS devices, the compliance policy includes settings for passcode complexity and length. App protection policies apply to apps, not device-wide settings; Conditional Access policies enforce access based on compliance but do not define the PIN requirement; Enrollment restrictions control which devices can enroll, not security settings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
App protection policy
Why it's wrong here
App protection policies safeguard corporate data within apps on enrolled and unenrolled devices, controlling app-level PIN and data-sharing behaviour. They cannot enforce a device-level passcode on enrolled iOS devices. It tempts because app protection policies do offer a PIN setting, but that PIN protects app data, not the device.
- ✓
Device compliance policy for iOS
Why this is correct
A device compliance policy for iOS defines the minimum PIN length requirement, enforcing a six-digit passcode as a condition of compliance. Device restrictions profiles control features, not passcode length, so compliance is the correct location.
- ✗
Conditional Access policy
Why it's wrong here
Conditional Access governs access to resources based on user, device and sign-in conditions; it cannot set a device passcode length. Device compliance and configuration profiles define passcode requirements. It tempts because Conditional Access can require compliant devices, but the PIN itself is configured in the compliance policy, not here.
- ✗
Enrollment restrictions
Why it's wrong here
Enrollment restrictions control which devices may enrol and under what platform or ownership conditions; they do not configure passcode length. Device compliance policies define passcode requirements for enrolled devices. It tempts because restrictions shape enrolment, but the six-digit PIN is a compliance setting applied after enrolment, not an enrolment gate.
Go deeper
Related to this question
Learn chapter
Troubleshooting Device Enrollment and Management
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.