Courseiva

MD-102 Manage and maintain devices Practice Question

Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that only devices with a passcode of at least 6 characters can access corporate email. What should you create?

⚠ Common exam trap

Watch out — candidates often confuse a device configuration profile (which enforces settings) with a device compliance policy (which evaluates and reports compliance), leading them to choose Option B instead of A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A device compliance policy with a required passcode length of 6.

A device compliance policy in Microsoft Intune evaluates whether devices meet specific security requirements, such as a minimum passcode length. By creating a compliance policy with a required passcode length of 6, Intune marks any iOS device with a shorter passcode as noncompliant. This noncompliant status can then be used by a conditional access policy to block access to corporate email, achieving the stated goal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A device compliance policy with a required passcode length of 6.

    Why this is correct

    A device compliance policy defines passcode requirements, including minimum length, for iOS devices. Setting the required passcode length to six characters enforces the stem's constraint before Microsoft Entra ID conditional access permits corporate email access.

  • ✗

    A device configuration profile with a passcode payload.

    Why it's wrong here

    A device configuration profile sets the passcode requirement on the device itself, but it does not gate corporate email access; a device failing the passcode still receives mail unless access is blocked. Configuration profiles are the right tool for enforcing device settings, not for restricting email based on those settings.

  • ✗

    An app protection policy for Microsoft Outlook.

    Why it's wrong here

    App protection policies control data handling within Outlook, such as cut/copy/paste and save-as, and can require a device PIN, but that PIN is app-level and independent of the iOS passcode length. They suit BYOD scenarios where devices are unenrolled and only app data must be protected.

  • ✗

    A conditional access policy requiring compliant devices.

    Why it's wrong here

    Conditional access requiring compliant devices blocks access based on compliance state, but compliance depends on a compliance policy defining the passcode rule; without that policy the 6-character requirement is never evaluated. Conditional access is the correct choice once a compliance policy exists to define the condition.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.