MD-102 Protect devices Practice Question
You need to deploy a Microsoft 365 Apps for enterprise configuration to devices managed by Intune. Which policy type should you use?
⚠ Common exam trap
Test-takers frequently confuse the Microsoft 365 Apps configuration policy with a device configuration profile or a managed apps policy, mistakenly thinking that general device policies can handle Office-specific deployment tasks, when in fact only the dedicated Microsoft 365 Apps policy provides the necessary ODT integration and update channel management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft 365 Apps (Windows) configuration policy
The Microsoft 365 Apps (Windows) configuration policy is the correct choice because it is specifically designed to manage the deployment, update settings, and configuration of Microsoft 365 Apps for enterprise on Intune-managed Windows devices. This policy type provides granular control over installation parameters, update channels, and app settings, directly aligning with the requirement to deploy a Microsoft 365 Apps configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Device configuration profile (settings catalog)
Why it's wrong here
A settings catalog profile configures Windows device settings such as security baselines, Wi-Fi and Defender preferences; it has no Microsoft 365 Apps deployment template. Office configuration requires the dedicated Microsoft 365 Apps app type. Settings catalog is correct for granular device settings, not application packaging.
- ✗
Managed apps policy
Why it's wrong here
Managed apps policies govern protection and access for mobile applications, including app-level conditional access and data transfer restrictions. They do not install Microsoft 365 Apps for enterprise on Windows endpoints. This policy fits securing mobile app data, not desktop Office deployment.
- ✗
Windows update ring policy
Why it's wrong here
Windows update ring policies govern quality and feature update deferrals, deadlines and restart behaviour for Windows devices. They carry no Microsoft 365 Apps installation or channel settings. Such a ring is the right choice when controlling when Windows patches apply, not when deploying Office.
- ✓
Microsoft 365 Apps (Windows) configuration policy
Why this is correct
Microsoft 365 Apps (Windows) configuration policies in Intune deploy and configure Office on Windows devices, letting you set update channels, remove previous installations, and choose specific apps. This directly satisfies the stem's requirement to deploy a Microsoft 365 Apps for enterprise configuration to Intune-managed devices, unlike settings catalog or compliance policies.
Go deeper
Related to this question
Learn chapter
Planning Deployment and Architecture
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
About these practice questions
This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.