Courseiva

MD-102 Prepare infrastructure for devices Practice Question

You need to configure Microsoft Intune to automatically retire a device if it has not checked in for 30 days. Where would you configure this setting?

⚠ Common exam trap

MD-102 often tests the confusion between device compliance (which evaluates health) and device cleanup (which retires inactive devices), leading candidates to choose compliance policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Intune device cleanup rules

Intune device cleanup rules allow you to automatically retire devices that have not checked in for a specified number of days. This setting is configured under Tenant Administration > Device Cleanup Rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Intune device cleanup rules

    Why this is correct

    Intune device cleanup rules automatically retire or delete devices that have not checked in for a specified number of days. Configuring the inactivity threshold to 30 days in this policy satisfies the stem's automatic retirement requirement.

  • ✗

    Conditional access policy

    Why it's wrong here

    Conditional access policies gate sign-in to cloud resources using signals like user, device compliance and location; they cannot retire an Intune device record after 30 days without check-in. They are tempting because they enforce access decisions automatically; they would be correct for requiring compliant devices or MFA at authentication time.

  • ✗

    Device compliance policy

    Why it's wrong here

    Compliance policies evaluate rules such as encryption, OS version and firewall status, and mark devices non-compliant; they contain no inactivity timer that retires a device. They are tempting because they drive automated remediation actions; they would be correct for blocking or notifying devices that fail security baselines, not for stale check-in cleanup.

  • ✗

    Device configuration profile

    Why it's wrong here

    Configuration profiles deliver settings and restrictions to devices, such as Wi-Fi, certificates or VPN parameters, and include no device retirement trigger based on check-in recency. They are tempting because they push automated configuration at scale; they would be correct for enforcing device settings, whereas stale-device cleanup belongs in the device cleanup rules under tenant enrolment settings.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.