Courseiva
Protect deviceshardMultiple ChoiceObjective-mapped

Device Compliant but Conditional Access Blocks: Certificate Troubleshooting

Your organization uses Microsoft Intune to manage devices. You have a Windows 10 device that is Azure AD joined and enrolled in Intune. The device is compliant, but the user cannot access corporate resources due to a Conditional Access policy requiring a compliant device. The user can access other cloud apps that do not require compliance. You check the Conditional Access policy and find it is configured correctly. What is the most likely issue?

Quick Answer

The answer is a missing or expired device certificate, requiring re-registration in Intune. When a device is compliant but blocked by Conditional Access due to certificate issues, the authentication token presented to Azure AD lacks a valid certificate-based claim, so the policy sees the device as non-compliant at the token level even though Intune’s compliance status shows green. This scenario tests your understanding of how Conditional Access evaluates device trust through certificates issued during enrollment, not just the compliance policy itself. On the MD-102 exam, this is a common trap: candidates see “compliant” in the console and assume the certificate is fine, but the token may be stale or the certificate chain broken. Remember that re-registering forces a fresh certificate and token, resolving the block. A useful memory tip: “Compliant in console, blocked in practice? Check the cert—re-register to refresh the pact.”

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The device's certificate is expired or missing; re-register the device in Intune.

Even though the device is compliant, the certificate used for authentication may be expired or missing, causing Conditional Access to block access. Re-registering the device in Intune refreshes the certificates and resolves the issue. Option A is incorrect because the policy is configured correctly and applies. Option C is incorrect because the device is enrolled in Intune. Option D is incorrect because the user is likely in the correct group as they can access other apps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The Conditional Access policy is not applied to the user.

    Why it's wrong here

    The user is blocked, so policy applies.

  • The device's certificate is expired or missing; re-register the device in Intune.

    Why this is correct

    Re-registration refreshes the certificate used for Conditional Access.

  • The device is not enrolled in Intune.

    Why it's wrong here

    Device is compliant, so enrolled.

  • The user is not in the correct group.

    Why it's wrong here

    Policy applies to all users.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 942 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MD-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Entra ID joined devices and Microsoft Intune for mobile device management. A user reports that their device is not receiving compliance policies. The device shows as 'Compliant' in Intune but the Conditional Access policy still blocks access. What should you verify first?

medium
  • A.Check if the compliance policy is assigned to the device's group.
  • B.Review the Conditional Access policy to ensure it requires compliant device.
  • C.Confirm the device is enrolled in Intune.
  • D.Verify the user is in the correct Azure AD group for Conditional Access.

Why B: The device shows as 'Compliant' in Intune, indicating enrollment and policy assignment are not the issue. The Conditional Access policy may be misconfigured to require a different condition (e.g., hybrid Azure AD join) or may not be set to require compliant device. Reviewing the policy ensures it enforces the correct requirement. Option A is incorrect because the device is already compliant, implying the policy is assigned. Option C is incorrect since the device is already enrolled (shown by compliance status). Option D is incorrect because group membership is irrelevant if the policy itself doesn't require a compliant device.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.