Courseiva
Manage and maintain devices →mediumMultiple Choice

Compliance State Reflects Last Sync; May Be Outdated

Exhibit

Get-MgDeviceManagementManagedDevice -ManagedDeviceId "12345678-1234-1234-1234-123456789012" | Select-Object -Property DeviceName, OperatingSystem, ComplianceState, LastSyncDateTime

Refer to the exhibit. You run a PowerShell command to retrieve a managed device's details. The ComplianceState is 'compliant' but the device has not synced in 7 days. What is the most likely reason?

Quick Answer

The answer is that the ComplianceState reflects the last sync and may be outdated. This is because Intune evaluates compliance only at the moment a device checks in; if a device has not synced in seven days, the stored compliance state simply shows the result from that last sync, even if the device has since fallen out of compliance. On the MD-102 exam, this concept tests your understanding that compliance state is a snapshot, not a real-time status, and it is a common trap to assume a compliant status means the device is currently secure. A key memory tip is to think of compliance state like a timestamped report card—it only tells you the grade from the last test, not the current performance.

⚠ Common exam trap

Microsoft Intune often tests the misconception that ComplianceState is a live, real-time indicator, when in fact it is a snapshot from the last successful sync, and candidates may incorrectly assume a compliant state means the device is currently secure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The ComplianceState reflects the last sync; the device may have changed compliance since.

The ComplianceState property in Microsoft Intune reflects the compliance status at the time of the last device check-in. If a device has not synced for 7 days, the stored ComplianceState is stale and may no longer represent the actual compliance posture. The device could have become non-compliant since its last sync due to policy changes, missing updates, or configuration drift, but Intune will not update the state until the next successful sync.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The ComplianceState reflects the last sync; the device may have changed compliance since.

    Why this is correct

    ComplianceState is a cached value populated at the last device check-in. With no sync for seven days, Intune has not re-evaluated the device, so the stored 'compliant' result may no longer reflect its actual state.

  • ✗

    The device is compliant but not syncing because it is turned off.

    Why it's wrong here

    A powered-off device cannot check in, so Intune retains the last reported 'compliant' state until the device syncs again. It is tempting because it explains the stale timestamp, but the question asks for the most likely reason given the exhibit, and a policy or assignment change is the intended cause.

  • ✗

    The device is no longer enrolled but shows compliant due to a reporting delay.

    Why it's wrong here

    A stale ComplianceState reflects the last reported check-in, not current enrolment; an unenrolled device would typically show non-compliant or be removed. It is tempting because reporting lag genuinely delays state updates, but that scenario involves recent sync failures, not seven days of silence.

  • ✗

    The compliance policy was removed after the last sync.

    Why it's wrong here

    Removing a compliance policy does not leave the device reporting 'compliant'; Intune would mark it non-compliant or unassigned at the next evaluation. It is tempting because policy changes do affect state, but the stale seven-day sync points to the device not checking in rather than to policy removal.

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MD-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Refer to the exhibit. You run this Microsoft Graph PowerShell command to retrieve managed devices. The output shows a device with a lastSyncDateTime of 5 days ago. What does this indicate?

hard
  • A.The device was enrolled 5 days ago.
  • B.The device is non-compliant.
  • C.The device is unenrolled.
  • ✓ D.The device has not communicated with Intune for 5 days.

Why D: The `lastSyncDateTime` property in Microsoft Graph for Intune-managed devices indicates the most recent time the device successfully checked in with the Intune service. A value of 5 days ago means the device has not communicated with Intune for 5 days, which could be due to network issues, device inactivity, or configuration problems. This does not inherently mean the device is non-compliant or unenrolled—it simply reflects the last successful sync.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.