MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
A user reports that they cannot access Microsoft Teams from their mobile device. Other Microsoft 365 services work fine. You verify that the device is compliant with Intune policies. What is the most likely cause?
⚠ Common exam trap
Candidates often assume device compliance alone guarantees access, overlooking that Conditional Access policies can impose app-level requirements that are separate from device health checks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Conditional Access policy requires an approved client app for Teams
A Conditional Access policy requiring an approved client app for Microsoft Teams would block access from a mobile device even if the device is Intune-compliant, as the policy specifically checks for the use of an approved app (e.g., the official Microsoft Teams app) rather than just device compliance. Since the user can access other Microsoft 365 services, the issue is isolated to Teams, and the device compliance status rules out broader device-level blocks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user's authentication method is not registered for Microsoft Entra ID
Why it's wrong here
The user's authentication method is not registered for Microsoft Entra ID. Authentication method registration is used during sign-in for secondary verification (e.g., MFA, self-service password reset), not for controlling access to a specific application after authentication. If the user successfully signed in to Microsoft Teams, their authentication method was already validated; a missing registered method would have failed at the sign-in or MFA challenge step, not at the Teams app authorization layer.
- ✗
The Microsoft Teams service is degraded
Why it's wrong here
The Microsoft Teams service is degraded. Service health incidents affect an entire tenant or a significant regional subset of users, not an isolated individual. A single user being unable to access Teams while others continue to work points to a user-, device-, or policy-specific issue, such as a Conditional Access rule or a stale local cache, rather than a platform-wide service degradation. In addition, the administrator would see an advisory in the Microsoft 365 admin center service health dashboard if Teams were genuinely degraded.
- ✓
A Conditional Access policy requires an approved client app for Teams
Why this is correct
A Conditional Access policy requires an approved client app for Teams. If the policy is configured under Conditional Access > Grant > 'Require approved client app' for the Microsoft Teams cloud app, access is allowed only when the requesting app is in the approved list and is protected by an Intune app protection policy (APP). The user is likely using a non-approved client (e.g., a web browser or a third-party Teams client) or an app that has not received the required APP policy, so the Conditional Access engine blocks the session even though sign-in succeeded. This is an app-level access control, which exactly matches the symptom of a single user (if other users are on compliant clients) or a device-specific gap.
- ✗
The device is not enrolled in Microsoft Intune
Why it's wrong here
The device is not enrolled in Microsoft Intune. Conditional Access policies that require a compliant or Microsoft Entra hybrid-joined device rely on Intune enrollment to report compliance state. Since the provided context states that the device is compliant, it must be enrolled in Intune; therefore, an enrollment problem cannot be the cause of the Teams access failure. Even if the device were unenrolled, the policy enforcement would surface as a compliance failure, which would be a valid but incorrect explanation because the device already satisfies the compliance requirement.
Go deeper
Related to this question
Learn chapter
Azure Active Directory Domain Services (AADDS)
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.