Courseiva
Protect devices →mediumMultiple Choice

MD-102 Protect devices Practice Question

You manage Windows 11 devices with Microsoft Intune. Security requires that when a device is marked as noncompliant, access to Microsoft 365 services is blocked within 5 minutes, even if the user is already signed in. You configure a Conditional Access policy that requires a compliant device. What else must you configure to achieve this near-real-time enforcement?

⚠ Common exam trap

The trap here is assuming that shortening the compliance validity period or marking unassigned devices as noncompliant will speed up enforcement, when actually only continuous access evaluation provides near-real-time token revocation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the Conditional Access policy to use 'Require device to be marked as compliant' and enable continuous access evaluation (CAE).

Continuous access evaluation (CAE) is the feature that enables near-real-time enforcement of Conditional Access policies. When a device becomes noncompliant, Intune updates the device compliance state, and CAE allows Microsoft Entra ID to revoke access tokens immediately. Without CAE, access remains until token expiry, which can be up to an hour. Therefore, enabling CAE alongside the compliant device requirement achieves the 5-minute block.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure the Conditional Access policy to use 'Require device to be marked as compliant' and enable continuous access evaluation (CAE).

    Why this is correct

    Continuous access evaluation (CAE) enables near-real-time enforcement of Conditional Access policies by allowing Microsoft Entra ID to revoke access tokens when a device's compliance state changes, rather than waiting for token expiry. Combined with a compliant device requirement, CAE ensures that a noncompliant device is blocked within minutes, meeting the 5-minute requirement without user reauthentication.

  • ✗

    Decrease the compliance policy's 'Compliance status validity period' to 5 minutes.

    Why it's wrong here

    The compliance status validity period defines how long a device's last reported compliance state is considered valid before it is re-evaluated. Setting it to 5 minutes would cause more frequent re-evaluation but does not push immediate revocation of existing sessions; access tokens remain valid until expiry. It does not provide the near-real-time blocking required here.

  • ✗

    Set the device compliance policy's action for noncompliance to 'Retire the device' immediately.

    Why it's wrong here

    Retiring a device removes corporate data and management, which is far too drastic and does not immediately block access to Microsoft 365 services. It also does not revoke already-issued tokens. The requirement is to block access quickly while preserving the device, so this action is inappropriate and ineffective for the scenario.

  • ✗

    Set the compliance policy's 'Mark devices with no compliance policy assigned as' setting to 'Not compliant'.

    Why it's wrong here

    This setting only affects devices that have no compliance policy assigned; it does not change how quickly an already-enforced policy reacts to a device becoming noncompliant. The delay in blocking is caused by the interval at which Intune reports compliance state to Microsoft Entra ID, not by unassigned devices. Therefore it will not deliver the required 5-minute enforcement.

Go deeper

Related to this question

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.