Courseiva
Manage and maintain devices →mediumMultiple Choice

MD-102 Manage and maintain devices Practice Question

You manage Windows 11 devices with Microsoft Intune. A security requirement states that when a device is marked as noncompliant, it must lose access to Microsoft 365 services within 15 minutes, but the device must not be wiped. You create a compliance policy and a conditional access policy. Which setting should you configure in the compliance policy to meet the time requirement?

⚠ Common exam trap

Test-takers frequently confuse device restriction or app protection policies with the compliance policy setting that controls the timing of the noncompliant state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the 'Mark device noncompliant' schedule to 15 minutes.

The 'Mark device noncompliant' schedule is the compliance policy setting that controls how quickly a failed compliance check transitions the device to a noncompliant state. Once noncompliant, the conditional access policy evaluates the device state and blocks access to Microsoft 365 services. The other options either apply to different policy types or perform destructive actions that violate the no-wipe requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an app protection policy with a 15-minute recheck interval.

    Why it's wrong here

    App protection policies (MAM) apply to apps on devices, including unmanaged ones, and control data transfer and access within apps. They do not set the compliance evaluation schedule for device compliance policies or drive conditional access blocking for the device as a whole. This does not satisfy the 15-minute access revocation requirement.

  • ✗

    Set the compliance policy action for noncompliance to 'Retire the device' after 15 minutes.

    Why it's wrong here

    Retire removes corporate data and management but does not immediately block access to Microsoft 365 services, and it is a destructive action that would remove the device from management. The requirement explicitly states the device must not be wiped or retired, so this action is inappropriate and does not achieve the timed access block.

  • ✗

    Configure a device restriction policy with a 15-minute grace period.

    Why it's wrong here

    Device restriction policies control hardware and OS features such as camera, USB, or password rules. They do not govern the timing of compliance state changes or conditional access enforcement. A grace period here would not mark the device noncompliant after 15 minutes, so it fails to meet the stated requirement.

  • ✓

    Set the 'Mark device noncompliant' schedule to 15 minutes.

    Why this is correct

    The 'Mark device noncompliant' schedule in the compliance policy defines how long after a device fails a check before Intune marks it noncompliant. Setting it to 15 minutes ensures the conditional access policy can block access within that window, without wiping the device. This is the direct control for the timing requirement in this scenario.

About these practice questions

One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.