MD-102 Compliance Policy Practice Question
You are managing devices with Microsoft Intune. You need to ensure that only compliant devices can access corporate email. Which TWO components should you configure?
⚠ Common exam trap
The trap is that candidates may mistakenly include additional components such as configuration profiles or app protection policies, not realizing that only two components are necessary: Compliance Policy and Conditional Access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compliance policy for Microsoft Intune
To ensure only compliant devices can access corporate email, you need a compliance policy (Option B) that defines device health rules and a Conditional Access policy (Option D) that enforces access based on compliance status. Option C is essentially the same concept as Option B and should not be selected as an additional component. Option A (device configuration profile) sets device settings but does not define compliance. Option E (app protection policy) protects app data but does not evaluate device compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Device configuration profile
Why it's wrong here
Device configuration profiles set device settings but do not define compliance rules.
- ✓
Compliance policy for Microsoft Intune
Why this is correct
Correct - defines compliance rules that devices must meet to be considered compliant.
- ✗
Device compliance policy
Why it's wrong here
This is the same concept as Option B (compliance policy for Microsoft Intune) and is not a separate component.
- ✓
Conditional Access policy in Microsoft Entra ID
Why this is correct
Correct - enforces access based on compliance status, granting or blocking access to corporate email.
- ✗
App protection policy
Why it's wrong here
App protection policies protect app data at the application level but do not evaluate device compliance.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Conditional Access policy
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
Key term
Device compliance
Device compliance is the process of ensuring that a device meets an organization's security and configuration policies before it can access network resources.
About these practice questions
This MD-102 question is part of Courseiva's 942-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.