Courseiva

MD-102 Prepare infrastructure for devices Practice Question

You are a Microsoft 365 Endpoint Administrator at Contoso. You have 200 Windows 11 devices enrolled in Microsoft Intune. The security team requires that all devices have a minimum OS build of 22621.1992 and that this requirement be enforced through a compliance policy. You need to configure the compliance policy in the Microsoft Intune admin center. Which policy type should you create?

⚠ Common exam trap

Candidates often confuse device configuration profiles, which configure settings, with compliance policies, which evaluate and report on device state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Device compliance policy for Windows 10 and later

A device compliance policy for Windows 10 and later is the correct choice because it includes a setting to require a minimum OS version. By setting the minimum OS version to 10.0.22621.1992, Intune will evaluate the OS build and mark devices that do not meet the requirement as noncompliant, which can then trigger conditional access or other actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Device compliance policy for Windows 10 and later

    Why this is correct

    A device compliance policy for Windows 10 and later allows you to specify a minimum OS version for Windows devices. You can set the required minimum OS version to 10.0.22621.1992, and Intune will evaluate the device's OS build and mark it noncompliant if it does not meet the requirement. This directly enforces the security team's requirement.

  • ✗

    Endpoint security policy for Windows 10 and later

    Why it's wrong here

    Endpoint security policies in Intune are used to manage security features like antivirus, firewall, and disk encryption. They do not include a setting to enforce a minimum OS version. Therefore, this policy type cannot satisfy the requirement to enforce a minimum OS build through compliance.

  • ✗

    Device configuration profile for Windows 10 and later

    Why it's wrong here

    Device configuration profiles are used to configure settings on devices, such as Wi-Fi, VPN, or certificates. They do not evaluate compliance or report noncompliance. While you could use a configuration profile to set some OS restrictions, it cannot enforce a minimum OS build as a compliance condition, so it fails to meet the requirement.

  • ✗

    App protection policy for Windows 10 and later

    Why it's wrong here

    App protection policies are used to protect corporate data within apps on devices, including Windows. They do not assess device compliance or enforce OS version requirements. They apply to apps, not the device itself, so they cannot enforce the minimum OS build requirement.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.