MD-102 Manage and maintain devices Practice Question
You manage 1,200 Windows 11 devices with Microsoft Intune. The security team reports that several devices have stopped checking in and may be compromised. You need to identify devices that have not contacted the service recently and then take action. Which TWO actions should you perform? (Choose two.)
⚠ Common exam trap
Many candidates confuse enrollment or provisioning properties with last check-in data; only the Last check-in column and lastSyncDateTime reflect recent device contact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In the Intune console, review the Devices > All devices list and sort or filter by the Last check-in column.
Identifying devices that have stopped checking in requires data on the last contact time. The Intune console's All devices view exposes a Last check-in column that can be sorted or filtered, and Microsoft Graph's managedDevices entity exposes lastSyncDateTime, which can be queried directly or through the Intune Data Warehouse. Provisioning state, enrollment date filtering, and compliance marking do not surface last check-in information, so they cannot reliably identify the stale devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a PowerShell script that imports the Intune module and calls Get-IntuneManagedDevice to list devices by enrollment date.
Why it's wrong here
The Intune PowerShell module and Graph-based cmdlets can list devices, but filtering by enrollment date returns devices based on when they were enrolled, not when they last checked in. This would include freshly enrolled devices that are active and omit old devices that are still healthy, so it fails to identify the stale devices the security team is concerned about.
- ✗
Create a dynamic device group that includes devices based on the deviceManagement.approvisioningState property.
Why it's wrong here
The provisioning state property reflects enrollment progress, not recent check-in activity. A device can be fully provisioned yet offline for weeks, so this rule would not surface stale devices. It also does not support the follow-up action of wiping a compromised device. Using it would produce a group that does not match the security team's concern about devices that have stopped checking in.
- ✓
In the Intune console, review the Devices > All devices list and sort or filter by the Last check-in column.
Why this is correct
The All devices list exposes a Last check-in column that can be sorted or filtered, making it the fastest way to identify devices that have not contacted Intune recently. It directly answers the requirement to find stale devices. From this view, an administrator can select a device and initiate a remote action such as wipe or retire, so it also supports the follow-up step.
- ✓
Use the Intune Data Warehouse or a Graph API query on managedDevices with the lastSyncDateTime property to identify stale devices.
Why this is correct
The managedDevices entity in Microsoft Graph exposes lastSyncDateTime, which records the last time the device contacted the service. Querying or reporting on this property, including through the Intune Data Warehouse, reliably identifies devices that have not checked in. This supports the requirement and provides an auditable list that can be used to drive remediation actions.
- ✗
Configure a compliance policy with the 'Unable to check in' rule set to 30 days and a noncompliance action of 'Mark device noncompliant'.
Why it's wrong here
This policy flags devices as noncompliant but does not identify them for the security team as a list to act on, nor does it perform any wipe or retire action. Marking noncompliant may trigger conditional access blocks, but the requirement is to identify stale devices and take action, which this setting alone does not accomplish. It also does not expose the underlying last check-in data.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.