Courseiva
Manage and maintain devices →mediumMultiple Choice

MD-102 Manage and maintain devices Practice Question

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that only devices with TPM 2.0 and Secure Boot enabled can access Microsoft 365 resources. What is the best approach?

⚠ Common exam trap

Many exam-takers think a Conditional Access policy alone can directly check hardware features, but it actually requires a compliance policy to report those attributes first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a device compliance policy requiring TPM and Secure Boot, and a Conditional Access policy to block non-compliant devices.

Device compliance policies in Microsoft Intune can evaluate hardware attributes like TPM version and Secure Boot status. When combined with a Conditional Access policy that blocks non-compliant devices, this enforces the security requirements before granting access to Microsoft 365 resources. This two-step approach ensures only devices meeting the hardware security baseline can authenticate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an app protection policy targeting Microsoft 365 apps.

    Why it's wrong here

    App protection policies govern data handling within Microsoft 365 apps on enrolled and unenrolled devices, and never inspect TPM version or Secure Boot state. They are the correct control when the requirement is restricting copy, save and share actions on mobile apps, not gating resource access on hardware attestation.

  • ✗

    Create a device configuration policy to enable TPM and Secure Boot.

    Why it's wrong here

    A device configuration policy can enforce TPM and Secure Boot settings on managed Windows 10 devices, but it only configures the hardware state; it does not block Microsoft 365 access from devices failing those checks. Configuration profiles are correct when the goal is remediating device settings rather than authorising resource access.

  • ✓

    Create a device compliance policy requiring TPM and Secure Boot, and a Conditional Access policy to block non-compliant devices.

    Why this is correct

    The compliance policy evaluates TPM 2.0 and Secure Boot state via device health attestation, marking non-compliant devices; Conditional Access then blocks their access to Microsoft 365 resources. This combination enforces the hardware constraint at authentication time rather than merely reporting it.

  • ✗

    Create a Conditional Access policy requiring TPM and Secure Boot.

    Why it's wrong here

    Conditional Access cannot evaluate TPM version or Secure Boot state; its device filters and compliance signals do not expose those hardware attestation attributes. It is tempting because Conditional Access does gate Microsoft 365 access on device compliance, which is the right mechanism when the requirement maps to a compliance policy rather than raw firmware state.

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.