Courseiva

MD-102 Prepare infrastructure for devices Practice Question

Your company uses Microsoft Intune to manage Windows devices. Users frequently work from public Wi-Fi and the security team is concerned about unmanaged devices accessing corporate resources. You need to ensure that only devices compliant with your security policies can access Microsoft 365 services. What should you implement?

⚠ Common exam trap

Many exam-takers confuse creating a compliance policy (which only defines the rules) with enforcing it via Conditional Access (which actually blocks access), leading them to select Option D instead of B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Conditional Access policies in Microsoft Entra ID that require compliant devices

Conditional Access policies in Microsoft Entra ID can require that devices accessing Microsoft 365 services be marked as compliant by Intune. This ensures that only devices meeting your security policies (e.g., encryption, antivirus, OS patch level) are granted access, directly addressing the security team's concern about unmanaged devices on public Wi-Fi.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy Windows Autopilot for all devices and require Entra ID join

    Why it's wrong here

    Autopilot provisions and Entra-joins corporate devices; it does not evaluate compliance of unmanaged personal devices before granting Microsoft 365 access. It is tempting because Autopilot standardises enrolment, which suits bulk device provisioning, yet the requirement is conditional access gated on device compliance.

  • ✓

    Configure Conditional Access policies in Microsoft Entra ID that require compliant devices

    Why this is correct

    Conditional Access evaluates device compliance state signalled by Intune, granting Microsoft 365 access only when the device meets security policies. This satisfies the requirement that unmanaged devices be blocked, since compliance policies alone cannot enforce access at the identity layer.

  • ✗

    Configure a VPN profile in Intune and enforce device compliance on the VPN server

    Why it's wrong here

    A VPN profile plus server-side compliance enforcement only governs traffic traversing that tunnel; Microsoft 365 is reached directly over the internet, bypassing it. It tempts because VPNs do restrict remote access, which suits protecting on-premises resources, not cloud services.

  • ✗

    Create a compliance policy in Intune and assign it to all users

    Why it's wrong here

    A compliance policy alone only marks devices compliant or not; it does not block Microsoft 365 sign-ins. It is tempting because compliance policies define the security rules, which suits reporting and conditional access inputs, but enforcement requires a conditional access policy targeting those signals.

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.