MD-102 Prepare infrastructure for devices Practice Question
You need to configure Microsoft Intune to automatically retire a device if it has not checked in for 30 days. Where would you configure this setting?
⚠ Common exam trap
MD-102 often tests the confusion between device compliance (which evaluates health) and device cleanup (which retires inactive devices), leading candidates to choose compliance policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Intune device cleanup rules
Intune device cleanup rules allow you to automatically retire devices that have not checked in for a specified number of days. This setting is configured under Tenant Administration > Device Cleanup Rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Intune device cleanup rules
Why this is correct
Intune device cleanup rules automatically retire or delete devices that have not checked in for a specified number of days. Configuring the inactivity threshold to 30 days in this policy satisfies the stem's automatic retirement requirement.
- ✗
Conditional access policy
Why it's wrong here
Conditional access policies gate sign-in to cloud resources using signals like user, device compliance and location; they cannot retire an Intune device record after 30 days without check-in. They are tempting because they enforce access decisions automatically; they would be correct for requiring compliant devices or MFA at authentication time.
- ✗
Device compliance policy
Why it's wrong here
Compliance policies evaluate rules such as encryption, OS version and firewall status, and mark devices non-compliant; they contain no inactivity timer that retires a device. They are tempting because they drive automated remediation actions; they would be correct for blocking or notifying devices that fail security baselines, not for stale check-in cleanup.
- ✗
Device configuration profile
Why it's wrong here
Configuration profiles deliver settings and restrictions to devices, such as Wi-Fi, certificates or VPN parameters, and include no device retirement trigger based on check-in recency. They are tempting because they push automated configuration at scale; they would be correct for enforcing device settings, whereas stale-device cleanup belongs in the device cleanup rules under tenant enrolment settings.
Go deeper
Related to this question
Learn chapter
Managing Microsoft 365 Apps and Office Updates
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.