MD-102 Manage and maintain devices Practice Question
You manage Windows 11 devices in Microsoft Intune. A compliance policy named 'Win11-Compliance' is assigned to all users. You need to prevent users whose devices are not compliant with 'Win11-Compliance' from accessing Microsoft 365 apps, but you want to allow a 30-minute grace period before access is blocked. What should you configure?
⚠ Common exam trap
The trap here is assuming that Conditional Access has a built-in grace period setting when it only enforces compliance status as evaluated by Intune.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy that requires compliant devices, and set the 'Grant' control to 'Require device to be marked as compliant'. Then, in the compliance policy, set the 'Action for noncompliance' to 'Mark device noncompliant' after 30 minutes.
To allow a grace period before blocking access, you must delay the device being marked noncompliant. Conditional Access itself does not provide a grace period. By configuring the compliance policy to mark the device noncompliant after 30 minutes, the device remains compliant during that time, and Conditional Access continues to allow access. After the delay, the device becomes noncompliant and access is blocked.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a Conditional Access policy that requires compliant devices, and set the 'Grant' control to 'Require device to be marked as compliant'. Then, in the compliance policy, set the 'Action for noncompliance' to 'Mark device noncompliant' after 30 minutes.
Why this is correct
This approach correctly uses Conditional Access to block noncompliant devices and leverages the compliance policy's noncompliance action schedule to delay marking the device noncompliant for 30 minutes. During that window, the device is still considered compliant, so access is allowed. After 30 minutes, the device is marked noncompliant and Conditional Access blocks access.
- ✗
Create a Conditional Access policy that requires compliant devices, and set the 'Grant' control to 'Require device to be marked as compliant' with a 30-minute session lifetime.
Why it's wrong here
Session lifetime controls how often sign-in conditions are re-evaluated, not a grace period before blocking. It does not delay enforcement of the compliance requirement. Users with noncompliant devices would still be blocked immediately upon sign-in, so this does not achieve the desired 30-minute grace period.
- ✗
Create a Conditional Access policy that requires compliant devices, and configure the 'Grant' control to 'Require device to be marked as compliant' with a 30-minute grace period.
Why it's wrong here
Conditional Access does not offer a 'grace period' setting under Grant controls. While you can require compliant devices, there is no built-in 30-minute delay before enforcing the block. This option describes a non-existent feature, so it cannot provide the required behavior.
- ✗
In the compliance policy, set 'Mark device noncompliant' to 30 minutes and assign the policy to all users.
Why it's wrong here
Setting the 'Mark device noncompliant' schedule to 30 minutes does not grant a 30-minute grace period for access. That setting defines how long after a compliance check failure the device is marked noncompliant, but access blocking occurs immediately once noncompliant unless a Conditional Access grace period is configured. It does not enforce a 30-minute window before access is blocked.
Go deeper
Related to this question
Learn chapter
Updating Devices with Windows Update for Business
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.