MD-102 Protect devices Practice Question
Your organization uses Microsoft Intune to manage Windows 11 devices. You need to ensure that only devices with a Trusted Platform Module (TPM) version 2.0 and Secure Boot enabled can access corporate email. What should you configure?
⚠ Common exam trap
MD-102 often tests the confusion between configuration policies (which set device settings) and compliance policies (which evaluate and enforce device state) — candidates pick the configuration option because it mentions Secure Boot, missing that enforcement requires a compliance policy plus conditional access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a compliance policy with device health rules.
Intune compliance policies include device health rules that can require specific hardware attributes such as TPM version and Secure Boot status. By creating a compliance policy with these device health requirements and then pairing it with a conditional access policy requiring a compliant device, you enforce that only devices meeting the TPM 2.0 and Secure Boot criteria can access corporate email. The compliance policy is the correct configuration object for defining these hardware requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a compliance policy with device health rules.
Why this is correct
A compliance policy with device health rules evaluates TPM version and Secure Boot status through the device health attestation service. Conditional Access can then require compliant devices before granting Exchange Online access, satisfying the requirement to restrict corporate email.
- ✗
Configure Windows Hello for Business with TPM requirement.
Why it's wrong here
Windows Hello for Business governs credential issuance and sign-in, not email access authorisation. Conditional Access with device compliance or Entra hybrid join, plus a compliance policy requiring TPM 2.0 and Secure Boot, gates corporate email; Hello would be correct for phishing-resistant sign-in.
- ✗
Create a conditional access policy that requires compliant device.
Why it's wrong here
A compliant-device conditional access policy checks Intune compliance state, which does not itself verify TPM 2.0 or Secure Boot. It tempts because compliance policies feed that signal, but the hardware attestation must be defined in the compliance policy first.
- ✗
Create a device configuration policy to enable Secure Boot.
Why it's wrong here
A device configuration policy can enable Secure Boot but cannot evaluate TPM version or Secure Boot state as an access condition. It tempts because configuration policies do set these hardware settings, and would be right if the goal were merely to turn Secure Boot on rather than gate email access.
Go deeper
Related to this question
Learn chapter
Implementing App Protection Policies (MAM)
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
About these practice questions
One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.