Courseiva
Manage and maintain devicesmediumMultiple ChoiceObjective-mapped

Using Compliance Policy to Retire Devices Not Checking In

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that devices that haven't checked in for 30 days are automatically retired. Which configuration should you implement?

Quick Answer

The correct answer is to configure a device compliance policy with a 'Mark device noncompliant' action after 30 days of no check-in and add an action for noncompliance to retire the device. This works because Intune’s compliance policies allow you to set a grace period for device check-in, and once that threshold is exceeded, the policy can automatically trigger a noncompliance action—such as retiring the device—effectively removing stale devices from management. On the MD-102 exam, this scenario tests your understanding of how compliance policies can enforce lifecycle management beyond simple security baselines, often appearing as a distractor where candidates mistakenly choose a device configuration profile or a conditional access policy. A common trap is confusing the “mark device noncompliant” setting with a simple alert; remember that the retire action must be explicitly added under “Actions for noncompliance.” Memory tip: think “30 days, then retire” as a clean sweep—compliance policy handles the clock, and the action handles the broom.

⚠ Common exam trap

Candidates often confuse Intune device cleanup rules (which simply remove stale device records from the console) with compliance policy actions (which can actually retire the device and revoke company data), leading them to select Option B incorrectly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure a device compliance policy with a 'Mark device noncompliant' action after 30 days of no check-in and add an action for noncompliance to retire the device.

Intune's compliance policies can be configured to mark devices as noncompliant after a specified period of no check-in (e.g., 30 days), and then trigger an action for noncompliance—such as retiring the device. This ensures that devices that have not communicated with Intune within the defined timeframe are automatically removed from management, meeting the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Set up an automatic enrollment policy that retires devices after 30 days of inactivity.

    Why it's wrong here

    Automatic enrollment policies handle enrollment, not device retirement.

  • Use the Intune device cleanup rules to automatically remove devices that haven't checked in for 30 days.

    Why it's wrong here

    Cleanup rules remove device records but do not trigger retirement actions like wiping or retiring.

  • Configure a device compliance policy with a 'Mark device noncompliant' action after 30 days of no check-in and add an action for noncompliance to retire the device.

    Why this is correct

    This directly enforces retirement after 30 days of inactivity.

  • Create a device configuration profile with a 'Device Health' setting to require check-in within 30 days.

    Why it's wrong here

    Configuration profiles do not enforce check-in frequency.

Go deeper

Related to this question

About these practice questions

One of 942 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MD-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You manage Windows 11 devices with Microsoft Intune. Some users report that their device is marked as noncompliant even though it meets all compliance rules. You discover that the devices have not checked in with Intune for over 30 days. What should you do to prevent this issue?

hard
  • A.Configure a device configuration profile to set the MDM enrollment URL.
  • B.Create a Conditional Access policy to block devices that haven't checked in.
  • C.In the device compliance policy, set the 'Days until device is considered noncompliant' option to 30.
  • D.Enable automatic re-enrollment for Windows devices in Intune.

Why D: The issue occurs because devices have not checked in with Intune for over 30 days, causing them to be marked noncompliant. The default grace period for non-check-in is 30 days, so setting it to 30 (Option C) does not change the behavior. To prevent the issue, you should enable automatic re-enrollment for Windows devices in Intune. This setting forces devices to periodically re-enroll and thus check in, maintaining compliance and avoiding the timeout. Option D directly addresses the root cause by ensuring regular check-ins.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.