MD-102 Protect devices Practice Question
You need to ensure that only authorized users can enroll devices in Microsoft Intune. Which setting should you configure?
⚠ Common exam trap
MD-102 often tests the distinction between controls that gate enrollment (enrollment restrictions) versus controls that evaluate enrolled devices (compliance policies) or gate resource access (conditional access), so candidates pick a policy that sounds security-related but does not actually block enrollment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enrollment restrictions
Enrollment restrictions in Microsoft Intune let administrators control which users and devices are permitted to enroll, including platform, OS version, device type, and user/group targeting. By scoping enrollment to authorized groups or blocking personal devices, only approved users can complete MDM enrollment. This is the native control designed specifically to gate Intune enrollment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enrollment restrictions
Why this is correct
Enrollment restrictions control which users may enrol devices and which platforms or device types they can register, directly satisfying the requirement that only authorised users enrol in Microsoft Intune. Configuring a device-type or platform restriction, plus assigning it to a group, blocks unauthorised accounts at enrolment rather than relying on post-enrolment compliance.
- ✗
Device categories
Why it's wrong here
Device categories are descriptive labels assigned to enrolled devices for reporting and grouping; they carry no authorisation logic. They are tempting because they organise devices, and would be correct for scoping policies or reports, but restricting which users may enrol requires Intune enrolment restrictions, not categorisation.
- ✗
Device compliance policies
Why it's wrong here
Device compliance policies evaluate already-enrolled devices against configuration rules and mark them compliant or not; they cannot prevent enrolment. They are tempting because they govern device state, and would be correct for blocking non-compliant devices from resources, but authorising enrolment requires Intune enrolment restrictions.
- ✗
Conditional access policies
Why it's wrong here
Conditional access policies gate access to cloud apps and resources after authentication; they do not restrict who may enrol a device into Intune. They are tempting because they control sign-in, and would be correct for limiting access to Exchange or SharePoint, but enrolment authorisation lives in Intune enrolment restrictions.
Go deeper
Related to this question
Learn chapter
Troubleshooting Device Enrollment and Management
Key term
MDM
MDM stands for Mobile Device Management, a technology that allows IT administrators to securely manage, monitor, and enforce policies on mobile devices like smartphones and tablets from a central console.
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.