MD-102 Manage and maintain devices Practice Question
You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. Users report that when they attempt to enroll a personally owned Windows device, enrollment is blocked. You need to allow only corporate-owned devices to enroll while still permitting personally owned devices to access email through a browser. What should you configure?
⚠ Common exam trap
Watch out — candidates often confuse enrollment restrictions, which gate enrollment, with compliance or conditional access policies, which evaluate or gate access after enrollment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a device enrollment restriction that blocks personally owned Windows devices and allow corporate-owned devices.
Enrollment restrictions in Intune are the mechanism for controlling whether personally owned devices can enroll for a given platform. By blocking personal Windows ownership while allowing corporate ownership, only corporate devices enroll. Because browser-based email access is controlled separately through conditional access, personal devices can still reach email in a browser without being enrolled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a device enrollment restriction that blocks personally owned Windows devices and allow corporate-owned devices.
Why this is correct
Device enrollment restrictions in Intune let you control which platforms and personal ownership types can enroll. By blocking personally owned Windows devices while allowing corporate-owned ones, you prevent personal devices from enrolling as managed endpoints. Users can still access email through a browser because browser access is governed by conditional access, not enrollment restrictions, so the requirement is met.
- ✗
Configure an Autopilot deployment profile that targets only corporate devices.
Why it's wrong here
Autopilot deployment profiles control the out-of-box experience for devices registered with Autopilot, but they do not prevent a personally owned Windows device from being manually enrolled through Settings. Enrollment restrictions are the correct control for blocking personal enrollment. Autopilot profiles alone cannot enforce the corporate-only enrollment requirement.
- ✗
Configure a conditional access policy that requires compliant devices for all cloud apps.
Why it's wrong here
Requiring compliant devices for all cloud apps would block personal devices from accessing email in a browser as well, because unmanaged browsers on unenrolled devices cannot satisfy the compliance requirement. This setting does not distinguish corporate from personal enrollment and instead restricts access broadly, which contradicts the requirement to allow browser-based email access on personal devices.
- ✗
Create a device compliance policy that requires BitLocker and mark personal devices as noncompliant.
Why it's wrong here
A compliance policy evaluates device state after enrollment and does not prevent enrollment itself. Personal devices could still enroll and then simply be marked noncompliant. This does not stop personal enrollment, and it may also block access in ways that conflict with allowing browser-based email access. Enrollment restrictions are the appropriate control.
Go deeper
Related to this question
Learn chapter
Implementing Windows Autopilot
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
Windows 11
Windows 11 is Microsoft's latest desktop operating system, offering a redesigned interface, enhanced security features, and improved support for modern hardware.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.