Courseiva
Protect devices →mediumMultiple Select

MD-102 Protect devices Practice Question

Which TWO actions should you take to ensure that only healthy Windows 10/11 devices can access Microsoft 365 services? (Choose two.)

⚠ Common exam trap

Many candidates confuse device enrollment (Option B) or provisioning (Option C) with ongoing health verification, but neither ensures the device remains healthy at the time of access; only the combination of a compliance policy with attestation checks and a Conditional Access policy that requires compliant device enforces this at authentication time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a device compliance policy that includes health attestation checks

Option A is correct because a device compliance policy in Microsoft Intune can include health attestation checks (e.g., BitLocker, Secure Boot, TPM, and code integrity via the Health Attestation Service), which determine whether a Windows 10/11 device meets the health and security baseline required to be marked compliant. Option E is correct because a Conditional Access policy that requires a compliant device enforces the compliance state at authentication time, blocking access to Microsoft 365 services from devices that are not marked compliant by Intune. Together, A defines what 'healthy' means and E enforces it for M365 access. Option B is not correct on its own because Intune enrollment is a prerequisite for compliance evaluation but does not itself ensure only healthy devices can access M365 services. Option C is not correct because Windows Autopilot only pre-provisions and configures devices; it does not gate access based on device health. Option D is not correct because app protection policies (MAM) protect app data on unmanaged or managed devices but do not enforce device health attestation for M365 service access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a device compliance policy that includes health attestation checks

    Why this is correct

    Health attestation in a Microsoft Entra ID compliance policy reports TPM-measured boot state, verifying Secure Boot, BitLocker and code integrity before granting access. This satisfies the stem's requirement that only healthy devices reach Microsoft 365 services, since non-compliant devices are blocked by Conditional Access.

  • ✗

    Configure Intune enrollment

    Why it's wrong here

    Intune enrollment only registers a device for management; it applies no health or compliance evaluation, so unenrolled-but-healthy and enrolled-but-unhealthy devices are both unaffected. It is tempting as the prerequisite for Conditional Access device signals, and would be correct when onboarding devices before compliance policies are assigned.

  • ✗

    Use Windows Autopilot to pre-provision devices

    Why it's wrong here

    Autopilot pre-provisions and enrols devices into Microsoft Entra ID, but it neither evaluates device health nor issues the compliance signal Conditional Access requires. It is tempting because it does streamline initial device deployment and Entra join, which would be correct when the requirement is zero-touch provisioning rather than health-gated access.

  • ✗

    Deploy an app protection policy to M365 apps

    Why it's wrong here

    App protection policies safeguard corporate data within M365 apps on any device, including unmanaged and non-compliant ones, so they cannot restrict access to healthy devices. They are tempting because they enforce M365 data controls, and would be correct for BYOD data leakage prevention.

  • ✓

    Create a Conditional Access policy that requires compliant device

    Why this is correct

    A Conditional Access policy requiring a compliant device blocks access from devices failing Intune compliance, enforcing the health requirement at authentication. Combined with health attestation, it ensures only healthy Windows 10/11 devices reach Microsoft 365 services.

About these practice questions

One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.