MD-102 Manage and maintain devices Practice Question
You manage Windows 10 devices with Microsoft Intune. A user reports that their device is not receiving required compliance policies, and the device status in Intune shows 'Not evaluated' for compliance. You confirm the device is enrolled and able to sync. What should you check first?
⚠ Common exam trap
Watch out — candidates often confuse 'Not evaluated' with a device health or configuration issue, when it actually points to a missing policy assignment or group membership problem.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the compliance policy is assigned to a group that includes the user or device.
A compliance policy must be assigned to a group containing the user or device for it to be evaluated. Even if the device is enrolled and syncing, without assignment the policy will not apply, resulting in a 'Not evaluated' status in Intune.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Verify that the user is assigned an Intune license.
Why it's wrong here
An unlicensed user cannot enrol, so the device would not appear as enrolled and syncing in Intune. Since enrolment and sync are confirmed, licensing is already satisfied. Verifying Intune licences is the right first step when a device fails to enrol or a user is missing from the portal entirely.
- ✗
Run the 'dsregcmd /status' command to check the device registration status.
Why it's wrong here
dsregcmd /status reports Microsoft Entra join and hybrid registration state, which does not govern Intune compliance evaluation; the 'Not evaluated' status instead points to missing or unassigned compliance policies. It is tempting because registration faults do block management, but the device is already enrolled and syncing.
- ✗
Check that the device has a TPM chip enabled and Secure Boot turned on.
Why it's wrong here
TPM and Secure Boot are prerequisites for specific compliance settings such as BitLocker, not for policy evaluation itself. 'Not evaluated' means the device has not processed the compliance policy at all, so hardware attestation state is irrelevant here. Checking TPM would be sensible when a BitLocker or Device Health Attestation rule reports an error.
- ✓
Ensure the compliance policy is assigned to a group that includes the user or device.
Why this is correct
A compliance policy showing 'Not evaluated' typically means no policy applies to that device or user. Verifying the policy's group assignment, ensuring the user or device is included, is the first check before investigating sync or client issues.
Go deeper
Related to this question
Learn chapter
Updating Devices with Windows Update for Business
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Compliance policy
A compliance policy is a set of rules that ensures devices, users, and applications meet an organization's security and regulatory requirements before they can access corporate resources.
About these practice questions
This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.