Courseiva

MD-102 Manage and maintain devices Practice Question

An organization uses Microsoft Intune to manage Windows devices. They want to ensure that only devices with a TPM 2.0 chip can access corporate email. Which policy should be configured?

⚠ Common exam trap

A common mix-up: candidates confuse device compliance policies with enrollment restrictions, thinking that blocking enrollment is sufficient, but Conditional Access is required to enforce access control after enrollment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Device compliance policy with a condition for TPM 2.0, combined with a conditional access policy

A device compliance policy can evaluate whether a device has TPM 2.0 (via the TPM specification version check), and when combined with a Conditional Access policy, it can block access to corporate email for non-compliant devices. This is the standard Microsoft approach for enforcing hardware-based security requirements for cloud app access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Device enrollment restriction to require TPM 2.0

    Why it's wrong here

    Enrollment restrictions gate whether a device may enrol into Intune at all, based on platform, version, or manufacturer. They cannot evaluate TPM 2.0 as an ongoing access condition for email. A compliance policy with a TPM requirement, enforced through Conditional Access, is what blocks non-compliant devices at sign-in.

  • ✗

    Device configuration profile to enable TPM 2.0

    Why it's wrong here

    A configuration profile can enable or configure TPM settings on enrolled hardware, but it cannot block email when TPM 2.0 is absent. Access gating needs a compliance policy rule that Conditional Access evaluates. Configuration profiles are the right choice for turning on BitLocker or setting TPM ownership, not for conditional access decisions.

  • ✓

    Device compliance policy with a condition for TPM 2.0, combined with a conditional access policy

    Why this is correct

    A device compliance policy evaluates the TPM 2.0 requirement as a device health attestation, marking non-compliant devices accordingly. Pairing it with a Microsoft Entra ID conditional access policy then enforces the grant control, blocking corporate email access from any device failing that check. This satisfies the stem's requirement that only TPM 2.0 devices reach email.

  • ✗

    App protection policy to require TPM 2.0

    Why it's wrong here

    App protection policies govern data handling within mobile apps via Intune MAM, not hardware attestation of Windows endpoints. TPM 2.0 gating of email access requires a compliance policy rule, which Conditional Access then enforces. App protection suits BYOD scenarios where you control app-level copy, paste and save behaviour rather than device silicon.

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.