Courseiva

MD-102 Manage and maintain devices Practice Question

You are troubleshooting a Windows 10 device that is not receiving a required security policy from Intune. The device shows as 'Not compliant' in the Intune console. Which TWO actions should you take to resolve the issue?

⚠ Common exam trap

It's easy for candidates to confuse Intune MDM policy delivery with traditional on-premises Group Policy, leading them to select the gpupdate command (Option E) instead of recognizing that Intune relies on OMA-DM sync and network connectivity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure the device is in the correct Microsoft Entra ID group targeted by the policy.

Option A is correct because Intune policies are assigned to Microsoft Entra ID groups, so if the device (or its user) is not a member of the group targeted by the security policy, the policy will never be delivered and the device will remain non-compliant. Option D is correct because Intune is a cloud-based MDM service; the device must have an active internet connection and be able to reach Intune endpoints (e.g., *.manage.microsoft.com over TCP 443) for policy sync, check-in, and compliance evaluation to occur. Option B is not relevant because Microsoft 365 licensing affects access to services like Exchange and Office, not Intune policy delivery or compliance state. Option C is not appropriate because resetting enrollment state via the Company Portal is a drastic remediation that removes management and would not fix a group-targeting or connectivity issue. Option E is incorrect because gpupdate /force applies on-premises Active Directory Group Policy, not Intune MDM policies, and Invoke-Command targets PowerShell remoting rather than Intune policy sync.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Ensure the device is in the correct Microsoft Entra ID group targeted by the policy.

    Why this is correct

    Policy assignment flows through Microsoft Entra ID group membership, so a device outside the targeted group never receives the configuration. Confirming correct group membership restores delivery of the security policy and clears the noncompliant state.

  • ✗

    Reissue the user's Microsoft 365 license from the admin center.

    Why it's wrong here

    Licensing governs service access, not policy assignment; a licensed user with a correctly targeted device still receives policy. Reissuing is tempting when a user cannot sign in or Intune reports an unlicensed state, but the device is enrolled and reporting compliance, so licensing is not the failing dependency.

  • ✗

    Reset the device's enrollment state via the Company Portal.

    Why it's wrong here

    Resetting enrollment state removes the device's Intune and Microsoft Entra ID registration, forcing re-enrolment and wiping work data; it does not deliver the missing policy. It tempts when a device is stale or duplicated, where re-enrolment genuinely fixes sync. Here the device already reports compliance status, so the management channel is intact.

  • ✓

    Verify that the device has an active internet connection and can reach Intune services.

    Why this is correct

    Intune policies reach devices through the Microsoft Intune service over the internet; without an active connection the device cannot check in, receive configuration, or update compliance status. Verifying connectivity to Intune services restores policy delivery and compliance evaluation.

  • ✗

    Run Invoke-Command to remotely execute gpupdate /force.

    Why it's wrong here

    gpupdate /force refreshes Group Policy from on-premises domain controllers; it has no effect on Intune MDM policy, which arrives via the MDM channel and the Intune Management Extension. It tempts on hybrid-joined devices where Group Policy and Intune coexist, but the stem concerns Intune policy delivery specifically.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.