Courseiva

MD-102 Manage and maintain devices Practice Question

Your organization uses Microsoft Intune and Microsoft Defender for Endpoint. You need to ensure that when a device is determined to be at high risk by Defender, it is automatically blocked from accessing corporate resources. What should you configure?

⚠ Common exam trap

Test-takers frequently think a device configuration policy or app protection policy can enforce risk-based blocking, but only the combination of a compliance policy with Defender risk evaluation and Conditional Access achieves this in Intune.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a device compliance policy that uses Defender for Endpoint risk level, then use Conditional Access.

It combines a device compliance policy that evaluates the Defender for Endpoint risk level with a Conditional Access policy that blocks access when the device is noncompliant. This is the only supported method to automatically block corporate resource access based on real-time risk assessment from Defender for Endpoint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a device compliance policy that uses Defender for Endpoint risk level, then use Conditional Access.

    Why this is correct

    Defender for Endpoint risk level feeds into Intune compliance policy, which marks the device non-compliant at high risk. Conditional Access then evaluates that compliance state and blocks access to corporate resources, satisfying the requirement for automatic blocking based on Defender's risk determination.

  • ✗

    Configure a device compliance policy with 'Require Defender for Endpoint' setting.

    Why it's wrong here

    A compliance policy with the Require Defender for Endpoint setting only marks a device compliant or non-compliant; it does not itself block resource access, which needs a conditional access policy acting on that signal. It is tempting because compliance policies feed access decisions, and would be correct for reporting device health rather than enforcing the block.

  • ✗

    Configure a device configuration policy to block access based on risk.

    Why it's wrong here

    Device configuration policies deliver settings such as firewall rules or encryption, and contain no risk-based conditional access evaluation, so they cannot block resources when Defender reports high risk. It is tempting because configuration policies are the usual Intune tool for enforcing device state, and would be correct for applying a hardening setting rather than gating access.

  • ✗

    Configure an app protection policy to block access based on device risk.

    Why it's wrong here

    App protection policies govern data handling within mobile apps on enrolled and unenrolled devices, and cannot evaluate Defender device risk to block corporate resource access. It is tempting because app protection policies do support some risk conditions, and would be correct for restricting copy-paste or save-as in managed apps rather than blocking the device.

Go deeper

Related to this question

About these practice questions

One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.