Courseiva
Protect devices →mediumMultiple Choice

MD-102 Protect devices Practice Question

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to ensure that all devices have a passcode of at least 6 characters and that devices are updated to the latest iOS version. You create a compliance policy. After assigning the policy, some devices are marked as non-compliant even though they have a passcode. What is the most likely cause?

⚠ Common exam trap

It's easy for candidates to assume compliance policies are evaluated immediately upon assignment, but Intune requires a device check-in to apply and evaluate the policy, and devices that haven't checked in will show as non-compliant even if they meet the requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The devices have not checked in with Intune since the policy was assigned.

Intune compliance policies are evaluated only when devices check in with the service. If a device has not performed a check-in since the policy was assigned, it will not have received or evaluated the new policy, and its compliance status will remain based on the previous state. The check-in interval for iOS/iPadOS devices is typically every 8 hours, but can be forced manually by the user. Until the device checks in, it cannot be marked compliant even if it meets the passcode and OS version requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The devices have multiple compliance policies applied.

    Why it's wrong here

    Multiple compliance policies combine with the most restrictive setting winning, so a stricter passcode or OS rule from another policy causes the non-compliance, not the passcode itself. It is tempting because conflicting assignments genuinely cause unexpected results, and would be correct if the stem described contradictory settings across policies.

  • ✗

    iOS devices do not support compliance policies.

    Why it's wrong here

    iOS/iPadOS devices fully support Intune compliance policies, including passcode and OS version rules, so this claim is factually false. It is tempting because platform differences do exist for some settings, and would be correct only for a platform genuinely lacking compliance support, which iOS is not.

  • ✓

    The devices have not checked in with Intune since the policy was assigned.

    Why this is correct

    Compliance state only refreshes when a device checks in with the Intune service. Until the device syncs and evaluates the newly assigned policy, it retains its previous status, so passcode-compliant devices can still appear non-compliant.

  • ✗

    The policy was assigned to a user group instead of a device group.

    Why it's wrong here

    Intune compliance policies target user groups; assignment scope does not prevent evaluation, so devices still receive and assess the policy. It is tempting because group targeting errors do cause deployment failures, and would be correct if the policy had been assigned to a group containing no relevant users.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.