Courseiva

MD-102 Prepare infrastructure for devices Practice Question

You are the administrator for a company that uses Microsoft Intune. The company has a policy that requires all Windows 10 devices to have a specific set of security settings applied via Intune configuration profiles. You need to ensure that these settings are applied to devices even if the user is not signed in, and that the settings cannot be overridden by the user. Which type of configuration profile should you use?

⚠ Common exam trap

Test-takers frequently confuse compliance policies with configuration profiles; compliance policies only evaluate, they do not apply settings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Device configuration profile with device scope.

Device configuration profiles with device scope apply settings directly to the device, independent of user sign-in, and enforce them so users cannot override. This meets the requirement of applying security settings even when no user is signed in. User-scoped profiles require sign-in, compliance policies only assess, and GPOs are not natively applied via Intune. Device-scoped profiles are the correct choice for device-wide security configurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Device configuration profile with user scope.

    Why it's wrong here

    A device configuration profile with user scope applies settings to users, not devices. It requires the user to sign in for the settings to apply, and it may allow user-specific exceptions. The requirement is to apply settings even when no user is signed in, and to prevent user override. User-scoped profiles do not meet these needs because they are tied to user sign-in and can be less restrictive. They are suitable for user-specific settings like email or Wi-Fi, but not for device-wide security settings.

  • ✓

    Device configuration profile with device scope.

    Why this is correct

    A device configuration profile with device scope applies settings directly to the device, independent of user sign-in. These settings are enforced by the device and cannot be overridden by users. This meets the requirement of applying settings even when no user is signed in and preventing user override. Device-scoped profiles are ideal for security settings that must apply globally, such as BitLocker, firewall, or Defender settings. They are assigned to device groups in Intune.

  • ✗

    Compliance policy.

    Why it's wrong here

    A compliance policy is used to evaluate device settings and report compliance status, but it does not apply settings. It can trigger conditional access but does not configure the device. The requirement is to apply security settings, not just assess them. Compliance policies are reactive and do not enforce configuration; they only mark devices as compliant or non-compliant. They are not the correct choice for applying settings that must be enforced regardless of user sign-in.

  • ✗

    Group Policy Object (GPO) via Intune.

    Why it's wrong here

    Group Policy Objects are not directly applied via Intune in a traditional sense; Intune uses MDM policies. While there is Group Policy analytics and some GPO settings can be migrated, Intune does not apply GPOs natively. The scenario specifies using Intune configuration profiles. GPOs require domain-joined devices and are processed at sign-in, which may not meet the requirement of applying settings without user sign-in. This option is not applicable in a pure Intune MDM scenario.

About these practice questions

One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.