MD-102 Prepare infrastructure for devices Practice Question
You are the Microsoft 365 Endpoint Administrator for Litware, Inc. Litware uses Microsoft Intune and has 500 Windows 11 devices that are already enrolled. The security team wants to require that all Windows devices use a specific set of compliance settings, and they want the settings to apply to devices in a specific department without affecting other departments. You need to deploy a compliance policy that targets only the department's devices. What should you do?
⚠ Common exam trap
The trap here is choosing user group targeting for a compliance policy, which can unintentionally apply to every device a user signs in to rather than only the department's corporate devices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a compliance policy and assign it to a group containing the department's devices.
Compliance policies are assigned to groups, and to affect only a specific department's devices, the policy should be assigned to a device group that contains those devices. Assigning to all devices with exclusions, using a configuration profile, or targeting users would either invert the scope, fail to produce a compliance signal, or inadvertently include devices outside the department. Device group targeting is the precise and standard method.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a compliance policy and assign it to a group containing the department's users.
Why it's wrong here
Assigning a compliance policy to a user group would apply the policy to all devices those users enroll or sign in to, potentially affecting devices outside the department, such as personal devices or shared devices. The requirement is to target the department's devices specifically, so a device group is the correct scope rather than a user group.
- ✓
Create a compliance policy and assign it to a group containing the department's devices.
Why this is correct
Compliance policies in Intune are assigned to groups, and assigning to a group that contains the department's devices scopes the policy to only those devices. This satisfies the requirement to apply settings to a specific department without affecting others. Device-based group targeting is the standard approach for scoping compliance policies to a subset of managed devices.
- ✗
Create a compliance policy and assign it to all devices, then exclude the department's devices.
Why it's wrong here
Excluding the department's devices would prevent the policy from applying to exactly the devices the security team wants covered. The requirement is to apply the policy to the department, not to everyone else. Assigning to all devices and excluding the target group inverts the intended scope and would leave the department unprotected.
- ✗
Create a device configuration profile and assign it to the department's devices.
Why it's wrong here
Device configuration profiles set device settings, such as restrictions or Wi-Fi, but they do not evaluate compliance state or feed Conditional Access. The security team's requirement is a compliance policy, which reports whether devices meet conditions. Using a configuration profile would not produce the compliance signal needed, so it does not meet the requirement.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.