MD-102 Prepare infrastructure for devices Practice Question
Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that work profile apps are encrypted and that the device owner cannot uninstall the Company Portal app. Which configuration profile should you deploy?
⚠ Common exam trap
Many exam-takers confuse 'Device restrictions for Android Enterprise work profile' with 'Device restrictions for Android Enterprise fully managed' or assume that a compliance policy can enforce configuration settings, when in fact the work profile restrictions profile is the only one that combines both encryption enforcement and app uninstall prevention for personally owned devices with work profiles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Device restrictions for Android Enterprise work profile
The 'Device restrictions for Android Enterprise work profile' profile includes settings to enforce encryption of work profile apps and to prevent the uninstallation of the Company Portal app. Specifically, the 'Require work profile encryption' setting ensures that work profile data is encrypted, and the 'Block uninstall of Company Portal' setting prevents the device owner from removing the Company Portal app. These settings are only available within the work profile restrictions profile, not in other profile types.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Device configuration profile with custom OMA-URI
Why it's wrong here
Custom OMA-URI is less reliable and harder to manage.
- ✗
Device restrictions for Android Enterprise fully managed
Why it's wrong here
This applies to corporate-owned devices, not work profile.
- ✓
Device restrictions for Android Enterprise work profile
Why this is correct
This profile can enforce encryption and block removal of apps.
- ✗
Compliance policy for Android Enterprise
Why it's wrong here
Compliance policies do not prevent uninstall.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
Key term
Configuration profile
A configuration profile is a set of settings and policies that can be applied remotely to devices to enforce security, compliance, and customization rules.
About these practice questions
This MD-102 question is part of Courseiva's 942-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.