MD-102 Protect devices Practice Question
Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to prevent users from installing apps from unknown sources on their personally-owned work profile devices. Which configuration profile type should you use?
⚠ Common exam trap
The trap here is selecting a custom profile thinking it's needed for granular control, but Intune provides a built-in device restrictions setting for this exact purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Device restrictions
To prevent installation of apps from unknown sources on Android Enterprise personally-owned work profile devices, you should use a device restrictions profile. This profile type includes a setting under 'Work Profile Settings' or 'Device Settings' to block unknown sources. It is the built-in, recommended method. Other profile types either do not apply to Android or do not have the specific setting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Custom
Why it's wrong here
Custom profiles allow you to deploy OMA-URI settings for specific device configurations. While you could potentially use a custom profile to set the unknown sources restriction, it is not the standard or recommended method. Intune provides built-in device restrictions for this purpose, making custom profiles unnecessary and more complex.
- ✗
Endpoint protection
Why it's wrong here
Endpoint protection profiles in Intune are used to configure security features like Microsoft Defender Antivirus, firewall, and encryption. They do not include settings to block app installation from unknown sources. This profile type is not appropriate for restricting app sources on Android devices.
- ✓
Device restrictions
Why this is correct
For Android Enterprise personally-owned work profile devices, device restrictions profiles include settings to block installation of apps from unknown sources. This directly prevents sideloading and meets the requirement. Device restrictions are used to control features like camera, Bluetooth, and app installation sources on managed devices.
- ✗
Identity protection
Why it's wrong here
Identity protection profiles are used to configure Windows Hello for Business and other identity-related settings. They do not apply to Android devices and do not control app installation sources. This profile type is irrelevant to the requirement of blocking unknown sources on Android.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Configuration profile
A configuration profile is a set of settings and policies that can be applied remotely to devices to enforce security, compliance, and customization rules.
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.