MD-102 Manage and maintain devices Practice Question
Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. You configure a Conditional Access policy in Microsoft Entra ID targeting Exchange Online. What else must you configure in Intune to enforce compliance?
⚠ Common exam trap
Watch out — candidates often assume Conditional Access policies are self-sufficient for compliance enforcement, overlooking that Intune compliance policies are the required mechanism to generate the compliance state that Conditional Access evaluates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Device compliance policies.
A is correct because Conditional Access policies in Microsoft Entra ID evaluate device compliance status, but they rely on Intune to report that status. Without a device compliance policy assigned to the device, Intune cannot mark the device as compliant, so the Conditional Access policy will block access or treat the device as non-compliant. You must create and assign a compliance policy in Intune that defines the required security baselines (e.g., encryption, OS version, jailbreak detection) for the device to be considered compliant.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Device compliance policies.
Why this is correct
Compliance policies must be configured and assigned to devices.
- ✗
No additional configuration is needed.
Why it's wrong here
Compliance policies are required for Conditional Access.
- ✗
Device configuration policies.
Why it's wrong here
Configuration policies do not enforce compliance.
- ✗
App protection policies.
Why it's wrong here
App protection policies are for app-level protection.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Conditional Access policy
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
About these practice questions
One of 942 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.