MD-102 Prepare infrastructure for devices Practice Question
Your organization plans to deploy Windows 365 Cloud PCs. You need to ensure that users can connect only from compliant devices. Which configuration should you implement?
⚠ Common exam trap
Candidates often confuse provisioning policies (which configure Cloud PCs) with access control policies (Conditional Access), leading them to select Option B, but provisioning policies do not enforce compliance-based access restrictions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy requiring device to be marked as compliant.
A Conditional Access policy that requires the device to be marked as compliant is the only configuration that enforces compliance at the authentication and access level. This policy evaluates the device's compliance status (reported by Microsoft Intune) before granting access to Windows 365 Cloud PCs, ensuring that only devices meeting your organization's compliance requirements can connect.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an app protection policy for Windows 365 app.
Why it's wrong here
App protection policies govern data within mobile apps, controlling copy, paste and save behaviour, not device compliance for Cloud PC connections. It is tempting for BYOD data containment, but the requirement is connection gating, which Conditional Access enforces using device compliance state.
- ✗
Configure the Cloud PC provisioning policy to allow only compliant devices.
Why it's wrong here
Provisioning policies define how Cloud PCs are created and assigned, not the conditions under which users may connect. It is tempting because it references compliance, but connection control is enforced by Conditional Access, which evaluates device compliance at sign-in.
- ✗
Assign a device compliance policy to all users.
Why it's wrong here
A device compliance policy only evaluates and marks device state; it does not itself block Cloud PC connections. It is tempting because compliance is a prerequisite, but enforcement requires a Conditional Access policy that grants Windows 365 access solely to compliant devices.
- ✓
Create a Conditional Access policy requiring device to be marked as compliant.
Why this is correct
A Conditional Access policy evaluates device compliance state at sign-in, so only devices marked compliant in Intune can establish the Cloud PC connection. This directly enforces the constraint that users connect solely from compliant devices.
Go deeper
Related to this question
Learn chapter
Enrolling Devices with Microsoft Intune
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.