Courseiva
Manage applications →mediumMultiple Select

MD-102 Manage applications Practice Question

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate applications. Which TWO configurations should you implement?

⚠ Common exam trap

A common mix-up: candidates confuse App Protection Policies (which protect data on unmanaged devices) with device compliance policies (which require managed devices to meet security baselines), leading them to select Option A instead of the correct combination of B and E.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a device compliance policy

Option B (Create a device compliance policy) is correct because a compliance policy in Intune defines the rules a device must meet—such as BitLocker, minimum OS version, or jailbreak/root detection—and evaluates devices to produce a compliance state that Conditional Access can consume. Option E (Create a Conditional Access policy requiring compliant devices) is correct because Conditional Access is the enforcement engine in Microsoft Entra ID that grants or blocks access to corporate applications based on signals like device compliance, so requiring compliant devices ensures only compliant devices reach those apps. Together, the compliance policy establishes the device state and the Conditional Access policy enforces it at access time. Option A (App Protection Policy) only protects app data on mobile apps via MAM and does not gate access to corporate applications based on device compliance. Option C (device configuration profile) merely configures settings on devices and does not itself evaluate or enforce compliance for access. Option D (MFA) strengthens user authentication but does not verify device compliance, so it does not satisfy the requirement on its own.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy an App Protection Policy

    Why it's wrong here

    App Protection Policies guard corporate data within apps on unmanaged or personally owned devices; they do not evaluate device compliance, so they cannot gate access on compliance state. They are tempting for BYOD data-leak control, but Conditional Access is what enforces compliant-device access to applications.

  • ✓

    Create a device compliance policy

    Why this is correct

    A compliance policy defines the rules a device must meet, such as encryption, PIN and OS version, and reports each device's state to Intune. Conditional Access then uses that state, so the policy is the prerequisite that produces the compliance signal.

  • ✗

    Configure a device configuration profile

    Why it's wrong here

    A device configuration profile sets settings such as Wi-Fi, certificates, or restrictions; it does not itself assess or enforce compliance, so it cannot restrict application access. It is tempting because configuration profiles feed compliance signals, but Conditional Access is the policy that actually blocks non-compliant devices.

  • ✗

    Enable multifactor authentication (MFA) for all users

    Why it's wrong here

    MFA strengthens authentication but does not evaluate device health, so it cannot gate access on compliance. It is tempting because it restricts access to trusted users, and it would be the right control when the requirement is verifying user identity rather than device state.

  • ✓

    Create a Conditional Access policy requiring compliant devices

    Why this is correct

    Conditional Access evaluates signals at sign-in and can require a device marked compliant by Intune before granting access to cloud apps. This enforces the restriction at the identity layer, blocking noncompliant devices regardless of app.

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.