MD-102 Protect devices Practice Question
You manage Windows 11 devices with Microsoft Intune. You need to configure a policy that will automatically lock the screen after 5 minutes of inactivity and require a password to unlock. Which policy type should you use?
⚠ Common exam trap
The trap here is assuming that a compliance policy can enforce settings; compliance policies only assess, while configuration profiles like Endpoint protection enforce.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Endpoint protection profile with 'Local device security options'
The Endpoint protection profile in Intune includes 'Local device security options' which allow you to configure the machine inactivity limit (screen lock timeout) and require a password on wakeup. Setting the inactivity limit to 300 seconds enforces a 5-minute lock, and the password requirement ensures unlock security. This is the most direct and supported method.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Endpoint protection profile with 'Local device security options'
Why this is correct
The Endpoint protection profile includes 'Local device security options' where you can configure interactive logon: Machine inactivity limit to 300 seconds (5 minutes) and require password on wakeup. This directly meets the requirement with precise control over screen lock timeout and password enforcement.
- ✗
Group Policy analytics profile
Why it's wrong here
Group Policy analytics is used to analyze existing on-premises GPOs and migrate them to Intune, not to directly configure new settings. It does not provide a way to deploy screen lock settings. Therefore, it is not the correct choice.
- ✗
Device restrictions configuration profile
Why it's wrong here
Device restrictions profiles include password and screen lock settings, but they are limited. They may not provide the granularity to set an inactivity timeout of exactly 5 minutes and enforce password unlock. They are more for broad restrictions like camera or Bluetooth, not precise screen lock timing.
- ✗
Compliance policy with 'Require a password to unlock mobile devices'
Why it's wrong here
Compliance policies only report on settings; they do not enforce them. Setting a compliance policy does not automatically configure the device to lock after 5 minutes. It would only mark the device non-compliant if it doesn't meet the criteria, but it does not apply the setting.
Go deeper
Related to this question
Learn chapter
Updating Devices with Windows Update for Business
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Screen lock
A security feature that prevents unauthorized access to a mobile device by requiring a specific action or credential to unlock the screen.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.