Courseiva
Manage and maintain devices →mediumMultiple Choice

MD-102 Manage and maintain devices Practice Question

You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. A security policy requires that devices be automatically marked as noncompliant if they have not checked in with Intune for more than 30 days. You need to configure this behavior with the least administrative effort. What should you do?

⚠ Common exam trap

The trap here is assuming that conditional access can directly evaluate the last check-in time of a device, when in fact compliance policies are responsible for marking devices noncompliant based on inactivity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a device compliance policy with the 'Device is inactive for a period of time' setting configured to 30 days.

The built-in compliance policy setting for device inactivity allows you to specify a number of days after which a device with no check-in is marked noncompliant. This is a native Intune feature that requires only configuring the compliance policy, with no custom scripting or additional services. Conditional access can then act on the noncompliant state, but the marking itself must come from the compliance policy. Therefore, the compliance policy with the inactivity rule is the correct and least-effort solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a device compliance policy with the 'Device is inactive for a period of time' setting configured to 30 days.

    Why this is correct

    The compliance policy setting 'Mark devices with no compliance policy assigned as' and specifically the 'Device is inactive' rule under Actions for noncompliance allows you to specify a number of days of inactivity. When a device does not check in within that period, Intune marks it noncompliant. This directly satisfies the requirement with minimal effort because it is a built-in compliance rule, not a custom script or conditional access policy.

  • ✗

    Configure a device configuration profile with a custom OMA-URI that sets an inactivity timeout.

    Why it's wrong here

    Device configuration profiles deliver settings to devices, but they do not control the compliance state in Intune. There is no OMA-URI that tells Intune to mark a device noncompliant after a period of no check-in. Compliance is evaluated by the Intune service based on compliance policies, not by settings pushed to the device. This approach would not achieve the desired automatic noncompliance marking.

  • ✗

    Create a conditional access policy that blocks access for devices not checked in for 30 days.

    Why it's wrong here

    Conditional access policies evaluate sign-in conditions such as device compliance state, but they do not track the last check-in time of a device. There is no condition for 'days since last Intune check-in' in Microsoft Entra conditional access. While you could block noncompliant devices, you still need a compliance policy to set the noncompliant state based on inactivity. This option alone does not meet the requirement.

  • ✗

    Use an Intune PowerShell script to query devices and mark them noncompliant if they have not checked in for 30 days.

    Why it's wrong here

    Intune PowerShell scripts run on devices, not in the service, and they cannot change the compliance state of a device directly. You would need to use Microsoft Graph to update the device compliance state, which requires custom automation, permissions, and ongoing maintenance. This is far more administrative effort than using the built-in compliance policy setting, and it is not the recommended approach.

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.