MD-102 Manage and maintain devices Practice Question
You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. A security policy requires that devices be automatically marked as noncompliant if they have not checked in with Intune for more than 30 days. You need to configure this behavior with the least administrative effort. What should you do?
⚠ Common exam trap
The trap here is assuming that conditional access can directly evaluate the last check-in time of a device, when in fact compliance policies are responsible for marking devices noncompliant based on inactivity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a device compliance policy with the 'Device is inactive for a period of time' setting configured to 30 days.
The built-in compliance policy setting for device inactivity allows you to specify a number of days after which a device with no check-in is marked noncompliant. This is a native Intune feature that requires only configuring the compliance policy, with no custom scripting or additional services. Conditional access can then act on the noncompliant state, but the marking itself must come from the compliance policy. Therefore, the compliance policy with the inactivity rule is the correct and least-effort solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a device compliance policy with the 'Device is inactive for a period of time' setting configured to 30 days.
Why this is correct
The compliance policy setting 'Mark devices with no compliance policy assigned as' and specifically the 'Device is inactive' rule under Actions for noncompliance allows you to specify a number of days of inactivity. When a device does not check in within that period, Intune marks it noncompliant. This directly satisfies the requirement with minimal effort because it is a built-in compliance rule, not a custom script or conditional access policy.
- ✗
Configure a device configuration profile with a custom OMA-URI that sets an inactivity timeout.
Why it's wrong here
Device configuration profiles deliver settings to devices, but they do not control the compliance state in Intune. There is no OMA-URI that tells Intune to mark a device noncompliant after a period of no check-in. Compliance is evaluated by the Intune service based on compliance policies, not by settings pushed to the device. This approach would not achieve the desired automatic noncompliance marking.
- ✗
Create a conditional access policy that blocks access for devices not checked in for 30 days.
Why it's wrong here
Conditional access policies evaluate sign-in conditions such as device compliance state, but they do not track the last check-in time of a device. There is no condition for 'days since last Intune check-in' in Microsoft Entra conditional access. While you could block noncompliant devices, you still need a compliance policy to set the noncompliant state based on inactivity. This option alone does not meet the requirement.
- ✗
Use an Intune PowerShell script to query devices and mark them noncompliant if they have not checked in for 30 days.
Why it's wrong here
Intune PowerShell scripts run on devices, not in the service, and they cannot change the compliance state of a device directly. You would need to use Microsoft Graph to update the device compliance state, which requires custom automation, permissions, and ongoing maintenance. This is far more administrative effort than using the built-in compliance policy setting, and it is not the recommended approach.
Go deeper
Related to this question
Learn chapter
Managing Conditional Access for Devices
Key term
Windows 11
Windows 11 is Microsoft's latest desktop operating system, offering a redesigned interface, enhanced security features, and improved support for modern hardware.
Key term
Compliance policy
A compliance policy is a set of rules that ensures devices, users, and applications meet an organization's security and regulatory requirements before they can access corporate resources.
About these practice questions
This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.