MD-102 Manage and maintain devices Practice Question
Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that only devices with TPM 2.0 and Secure Boot enabled can access Microsoft 365 resources. What is the best approach?
⚠ Common exam trap
Many exam-takers think a Conditional Access policy alone can directly check hardware features, but it actually requires a compliance policy to report those attributes first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a device compliance policy requiring TPM and Secure Boot, and a Conditional Access policy to block non-compliant devices.
Device compliance policies in Microsoft Intune can evaluate hardware attributes like TPM version and Secure Boot status. When combined with a Conditional Access policy that blocks non-compliant devices, this enforces the security requirements before granting access to Microsoft 365 resources. This two-step approach ensures only devices meeting the hardware security baseline can authenticate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an app protection policy targeting Microsoft 365 apps.
Why it's wrong here
App protection policies govern data handling within Microsoft 365 apps on enrolled and unenrolled devices, and never inspect TPM version or Secure Boot state. They are the correct control when the requirement is restricting copy, save and share actions on mobile apps, not gating resource access on hardware attestation.
- ✗
Create a device configuration policy to enable TPM and Secure Boot.
Why it's wrong here
A device configuration policy can enforce TPM and Secure Boot settings on managed Windows 10 devices, but it only configures the hardware state; it does not block Microsoft 365 access from devices failing those checks. Configuration profiles are correct when the goal is remediating device settings rather than authorising resource access.
- ✓
Create a device compliance policy requiring TPM and Secure Boot, and a Conditional Access policy to block non-compliant devices.
Why this is correct
The compliance policy evaluates TPM 2.0 and Secure Boot state via device health attestation, marking non-compliant devices; Conditional Access then blocks their access to Microsoft 365 resources. This combination enforces the hardware constraint at authentication time rather than merely reporting it.
- ✗
Create a Conditional Access policy requiring TPM and Secure Boot.
Why it's wrong here
Conditional Access cannot evaluate TPM version or Secure Boot state; its device filters and compliance signals do not expose those hardware attestation attributes. It is tempting because Conditional Access does gate Microsoft 365 access on device compliance, which is the right mechanism when the requirement maps to a compliance policy rather than raw firmware state.
Go deeper
Related to this question
Learn chapter
Managing Microsoft 365 Apps and Office Updates
Key term
Secure boot
Secure Boot is a security feature that ensures a device starts up using only trusted software that is digitally signed by the manufacturer.
Key term
TPM
TPM (Trusted Platform Module) is a dedicated hardware chip on a computer's motherboard that stores cryptographic keys, passwords, and certificates to secure the system against unauthorized access and tampering.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.