MD-102 Manage applications Practice Question
An organization uses Microsoft Intune to manage iOS/iPadOS devices. They have a custom line-of-business (LOB) iOS app that must be deployed to 50 devices. The app is signed with an enterprise certificate. The administrator uploads the .ipa file to Intune and assigns it as 'Required' to a device group containing the 50 devices. After 24 hours, only 30 devices have the app installed. The remaining 20 devices show 'pending install' status. What is the most likely cause?
⚠ Common exam trap
It's easy for candidates to assume 'pending install' means a user action is required (like opening Company Portal) or a network issue, but Microsoft Intune's MDM channel can push apps silently; the real blocker is certificate trust for enterprise-signed apps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The devices do not have a trusted certificate profile that trusts the enterprise signing certificate.
The most likely cause is that the 20 devices lack a trusted certificate profile that trusts the enterprise signing certificate. For an enterprise-signed LOB app to install on iOS/iPadOS, the device must trust the root certificate used to sign the app. Without a trusted certificate profile deployed via Intune, the installation will remain in 'pending install' status because the device cannot validate the app's signature.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The .ipa file exceeds the maximum file size allowed for LOB apps.
Why it's wrong here
iOS app size limits are higher; this is unlikely.
- ✗
The users on the 20 devices have not opened the Company Portal app to trigger the installation.
Why it's wrong here
Required LOB apps install silently without user interaction.
- ✓
The devices do not have a trusted certificate profile that trusts the enterprise signing certificate.
Why this is correct
Enterprise-signed apps require the device to trust the root certificate.
- ✗
The MDM push certificate has expired, preventing app installation.
Why it's wrong here
Push certificate affects enrollment, not app installation.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Device group
A device group is a logical collection of devices managed together for applying policies, configurations, and updates in an enterprise IT environment.
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
About these practice questions
Courseiva writes every MD-102 question from scratch — 942 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.