Courseiva
Protect devices →easyMultiple Choice

MD-102 Protect devices Practice Question

You need to ensure that only authorized users can enroll devices in Microsoft Intune. Which setting should you configure?

⚠ Common exam trap

MD-102 often tests the distinction between controls that gate enrollment (enrollment restrictions) versus controls that evaluate enrolled devices (compliance policies) or gate resource access (conditional access), so candidates pick a policy that sounds security-related but does not actually block enrollment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enrollment restrictions

Enrollment restrictions in Microsoft Intune let administrators control which users and devices are permitted to enroll, including platform, OS version, device type, and user/group targeting. By scoping enrollment to authorized groups or blocking personal devices, only approved users can complete MDM enrollment. This is the native control designed specifically to gate Intune enrollment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enrollment restrictions

    Why this is correct

    Enrollment restrictions control which users may enrol devices and which platforms or device types they can register, directly satisfying the requirement that only authorised users enrol in Microsoft Intune. Configuring a device-type or platform restriction, plus assigning it to a group, blocks unauthorised accounts at enrolment rather than relying on post-enrolment compliance.

  • ✗

    Device categories

    Why it's wrong here

    Device categories are descriptive labels assigned to enrolled devices for reporting and grouping; they carry no authorisation logic. They are tempting because they organise devices, and would be correct for scoping policies or reports, but restricting which users may enrol requires Intune enrolment restrictions, not categorisation.

  • ✗

    Device compliance policies

    Why it's wrong here

    Device compliance policies evaluate already-enrolled devices against configuration rules and mark them compliant or not; they cannot prevent enrolment. They are tempting because they govern device state, and would be correct for blocking non-compliant devices from resources, but authorising enrolment requires Intune enrolment restrictions.

  • ✗

    Conditional access policies

    Why it's wrong here

    Conditional access policies gate access to cloud apps and resources after authentication; they do not restrict who may enrol a device into Intune. They are tempting because they control sign-in, and would be correct for limiting access to Exchange or SharePoint, but enrolment authorisation lives in Intune enrolment restrictions.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.