Courseiva
Manage and maintain devices →mediumMultiple Choice

MD-102 Manage and maintain devices Practice Question

You manage a set of iOS/iPadOS devices enrolled in Microsoft Intune. You need to ensure that users cannot copy data from a managed corporate app (e.g., Outlook) to a personal app (e.g., Gmail). The solution must not require user interaction. What should you configure?

⚠ Common exam trap

The trap here is assuming that device configuration profiles can control inter-app data sharing, but that capability is exclusive to app protection policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an app protection policy with the 'Restrict cut, copy, and paste between other apps' setting set to 'Blocked'.

App protection policies in Intune provide granular control over data sharing between apps. The setting to restrict cut, copy, and paste between other apps, when set to Blocked, prevents data from being copied from a managed app to any unmanaged app. This is enforced at the app level and does not require user action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy a device configuration profile with the 'Allow copy and paste' setting set to 'Blocked'.

    Why it's wrong here

    Device configuration profiles for iOS/iPadOS do not include a setting to block copy and paste between apps. Such restrictions are only available through app protection policies. Device-level restrictions are typically for hardware features like camera or AirDrop, not for inter-app data sharing.

  • ✓

    Create an app protection policy with the 'Restrict cut, copy, and paste between other apps' setting set to 'Blocked'.

    Why this is correct

    App protection policies (also known as MAM policies) can restrict data transfer between managed and unmanaged apps. Setting 'Restrict cut, copy, and paste between other apps' to 'Blocked' prevents copying from a managed app to any unmanaged app, including personal apps like Gmail. This is enforced without user interaction and meets the requirement.

  • ✗

    Set the 'Require managed pasteboard' option in the app configuration policy for Outlook.

    Why it's wrong here

    The 'Require managed pasteboard' setting (available in some platforms) forces the use of a managed clipboard for copy/paste operations, but it does not block copying to unmanaged apps. It only ensures that data copied within managed apps stays within the managed ecosystem if the destination app also supports the managed pasteboard. It does not prevent copying to personal apps like Gmail.

  • ✗

    Configure a conditional access policy that requires compliant devices.

    Why it's wrong here

    Conditional access controls access to corporate resources based on device compliance or user conditions, but it does not restrict data sharing between apps on the device. It cannot prevent copying from a managed app to a personal app. This approach addresses access, not data leakage.

Go deeper

Related to this question

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.