MD-102 Prepare infrastructure for devices Practice Question
Your organization uses Microsoft Intune to manage devices. You need to ensure that devices that are not compliant are blocked from accessing corporate resources. Which configuration should you use?
⚠ Common exam trap
Test-takers frequently confuse the role of a compliance policy (which only evaluates and reports) with the enforcement mechanism (Conditional Access), leading them to select Option A as the answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy that requires compliant devices.
Conditional Access policies in Microsoft Entra ID are the correct mechanism to enforce access controls based on device compliance status. By creating a policy that requires devices to be marked as compliant, you ensure that only compliant devices can access corporate resources, while non-compliant devices are blocked at the authentication level. This integrates with Intune compliance policies to evaluate device health before granting access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a device compliance policy and assign it to users.
Why it's wrong here
A compliance policy only evaluates and reports device state; it does not itself block access. Conditional Access is what enforces the grant requirement against that state. It is tempting because compliance policies define the rules, and they would be correct when the goal is measuring and reporting compliance rather than denying access.
- ✗
Create a device configuration profile that restricts access.
Why it's wrong here
Device configuration profiles deliver settings such as Wi-Fi, certificates and restrictions to devices; they do not evaluate compliance state or gate resource access. It is tempting because configuration profiles shape device behaviour, and they would be correct when hardening settings or deploying certificates to managed devices.
- ✓
Create a Conditional Access policy that requires compliant devices.
Why this is correct
Conditional Access evaluates sign-in signals at authentication time, so a policy granting access only when the device is marked compliant in Intune blocks non-compliant devices from corporate resources. Compliance policies alone only report state; the Conditional Access policy enforces the block.
- ✗
Configure enrollment restrictions to block non-compliant devices.
Why it's wrong here
Enrollment restrictions govern which devices may enrol and their platform or ownership attributes, not ongoing access decisions for already-enrolled devices. It is tempting because restrictions control device admission, and they would be correct when blocking personally owned or unsupported platforms from enrolling at all.
Go deeper
Related to this question
Learn chapter
Enrolling Devices with Microsoft Intune
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.