MD-102 Prepare infrastructure for devices Practice Question
Your company uses Microsoft Intune to manage Windows devices. Users frequently work from public Wi-Fi and the security team is concerned about unmanaged devices accessing corporate resources. You need to ensure that only devices compliant with your security policies can access Microsoft 365 services. What should you implement?
⚠ Common exam trap
Many exam-takers confuse creating a compliance policy (which only defines the rules) with enforcing it via Conditional Access (which actually blocks access), leading them to select Option D instead of B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Conditional Access policies in Microsoft Entra ID that require compliant devices
Conditional Access policies in Microsoft Entra ID can require that devices accessing Microsoft 365 services be marked as compliant by Intune. This ensures that only devices meeting your security policies (e.g., encryption, antivirus, OS patch level) are granted access, directly addressing the security team's concern about unmanaged devices on public Wi-Fi.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy Windows Autopilot for all devices and require Entra ID join
Why it's wrong here
Autopilot provisions and Entra-joins corporate devices; it does not evaluate compliance of unmanaged personal devices before granting Microsoft 365 access. It is tempting because Autopilot standardises enrolment, which suits bulk device provisioning, yet the requirement is conditional access gated on device compliance.
- ✓
Configure Conditional Access policies in Microsoft Entra ID that require compliant devices
Why this is correct
Conditional Access evaluates device compliance state signalled by Intune, granting Microsoft 365 access only when the device meets security policies. This satisfies the requirement that unmanaged devices be blocked, since compliance policies alone cannot enforce access at the identity layer.
- ✗
Configure a VPN profile in Intune and enforce device compliance on the VPN server
Why it's wrong here
A VPN profile plus server-side compliance enforcement only governs traffic traversing that tunnel; Microsoft 365 is reached directly over the internet, bypassing it. It tempts because VPNs do restrict remote access, which suits protecting on-premises resources, not cloud services.
- ✗
Create a compliance policy in Intune and assign it to all users
Why it's wrong here
A compliance policy alone only marks devices compliant or not; it does not block Microsoft 365 sign-ins. It is tempting because compliance policies define the security rules, which suits reporting and conditional access inputs, but enforcement requires a conditional access policy targeting those signals.
Go deeper
Related to this question
Learn chapter
Implementing BitLocker and Device Encryption
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.