MD-102 Manage and maintain devices Practice Question
Your company uses Microsoft Intune to manage Windows 11 devices. You need to ensure that when a device is marked as noncompliant, it loses access to Microsoft 365 services within 15 minutes, without affecting compliant devices. You have already created a compliance policy and assigned it to all users. What should you configure next?
⚠ Common exam trap
Many candidates confuse Intune compliance policy actions with conditional access enforcement, when only conditional access can block access to cloud apps based on compliance state.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A conditional access policy in Microsoft Entra ID that requires compliant devices and set the grant control to 'Require device to be marked as compliant'.
Conditional access in Microsoft Entra ID enforces access controls based on conditions such as device compliance. By creating a policy that requires compliant devices for Microsoft 365 apps, noncompliant devices are blocked from accessing those services. This integrates with Intune compliance policies, which evaluate and report device state. The other options do not provide real-time access blocking based on compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A device compliance policy in Intune with an action for noncompliance that marks the device as noncompliant immediately.
Why it's wrong here
Compliance policies define rules and actions for noncompliance, such as sending email notifications or retiring the device, but they do not directly block access to Microsoft 365 services. The action for noncompliance can retire a device, but that is not a real-time access block. Conditional access is required to enforce access control based on compliance state.
- ✗
A configuration profile in Intune that sets the device to block access to Microsoft 365 services when noncompliant.
Why it's wrong here
Configuration profiles configure device settings and restrictions, but they do not integrate with Microsoft Entra ID to block cloud service access based on compliance. There is no configuration profile setting that directly blocks Microsoft 365 access upon noncompliance. Conditional access is the correct tool for this requirement.
- ✓
A conditional access policy in Microsoft Entra ID that requires compliant devices and set the grant control to 'Require device to be marked as compliant'.
Why this is correct
Conditional access policies in Microsoft Entra ID evaluate device compliance state and can block access to cloud apps when a device is noncompliant. By requiring compliant devices, noncompliant devices are denied access to Microsoft 365 services. The timing depends on token lifetime and compliance re-evaluation, but this is the correct mechanism to enforce compliance-based access.
- ✗
A Microsoft Defender for Endpoint device group in Intune with an automated task to restrict access.
Why it's wrong here
Defender for Endpoint device groups are used for managing security settings and automated investigations, not for enforcing conditional access to Microsoft 365 services. While Defender can contribute to risk signals, it does not directly block access based on Intune compliance. Conditional access is the appropriate feature for this scenario.
Go deeper
Related to this question
Learn chapter
Configuring Compliance Policies
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Compliance policy
A compliance policy is a set of rules that ensures devices, users, and applications meet an organization's security and regulatory requirements before they can access corporate resources.
About these practice questions
One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.