You manage a fleet of Windows 10 devices with Microsoft Intune. You need to ensure that when a device is marked as noncompliant, it loses access to corporate email and Teams within 15 minutes. You have already configured a compliance policy and assigned it to all users. What should you do next to meet the requirement?
A Conditional Access policy that requires compliant devices and uses the grant control 'Require device to be marked as compliant' will block access from devices that are not compliant. When a device becomes noncompliant, Intune marks it as such, and Conditional Access evaluates the device state. Access is typically blocked within minutes, meeting the 15-minute requirement. This is the correct approach to enforce compliance for access to corporate resources.
Why this answer
To block access to corporate resources like email and Teams when a device is noncompliant, you must use Conditional Access. A Conditional Access policy that requires the device to be marked as compliant will deny access if the device is not compliant. Intune updates the compliance status, and Conditional Access enforces it.
This typically takes effect within minutes, satisfying the 15-minute window. Other options do not provide the required enforcement.
Exam trap
The trap here is thinking that app protection policies or MFA can enforce device compliance; they cannot block access based on device compliance status.