Courseiva

MD-102 Manage and maintain devices Practice Question

Exhibit

{
  "@odata.type": "#microsoft.graph.windows10CompliancePolicy",
  "description": "Require BitLocker and Secure Boot",
  "deviceThreatProtectionEnabled": true,
  "deviceThreatProtectionRequiredSecurityLevel": "medium",
  "bitLockerEnabled": true,
  "secureBootEnabled": true,
  "osMinimumVersion": "10.0.19042.0"
}

Refer to the exhibit. You are reviewing a Windows 10 compliance policy JSON. What is the purpose of the 'osMinimumVersion' setting?

⚠ Common exam trap

Microsoft often tests the distinction between compliance evaluation (osMinimumVersion) and update enforcement (feature update policies or update rings), leading candidates to incorrectly assume that a compliance setting can force an update.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It defines the minimum OS build version that the device must have to be compliant.

The 'osMinimumVersion' setting in a Windows 10 compliance policy specifies the minimum OS build version (e.g., 10.0.19041) that a device must have to be considered compliant. If the device's OS build version is lower than this value, Intune marks it as non-compliant, which can trigger conditional access blocks or remediation actions. This setting does not initiate an update; it only evaluates the current version against the defined threshold.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It sets the Windows Update for Business ring to that version.

    Why it's wrong here

    The setting defines the minimum OS build a device must run to be marked compliant; it does not configure update rings. Update rings are tempting because they also reference versions, but they belong to Windows Update for Business policies that schedule and defer feature updates, not to compliance evaluation.

  • ✗

    It requires the device to be on a specific feature update.

    Why it's wrong here

    The `osMinimumVersion` setting enforces a floor on the OS build number, not a specific feature update; a device on any later build still passes. It is tempting because feature-update control is a genuine compliance need, and it would be the right choice when the requirement is to pin devices to one exact Windows release.

  • ✓

    It defines the minimum OS build version that the device must have to be compliant.

    Why this is correct

    The osMinimumVersion setting in a compliance policy specifies the lowest acceptable OS build; devices below it are marked non-compliant. This satisfies the requirement to enforce a minimum Windows build, letting Intune flag outdated devices and trigger remediation or conditional access blocks.

  • ✗

    It forces the device to update to that version.

    Why it's wrong here

    Compliance policies only report and conditionally block access; they never push updates to devices. Forcing installation is the role of update rings or feature update policies in Microsoft Intune, which is why the wording misleads.

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.