Courseiva

Block Unmanaged Device Access: Conditional Access + Intune

Your organization uses Microsoft 365 and has strict compliance requirements. The compliance officer has noticed that some users are able to access sensitive documents from unmanaged devices. You need to ensure that all access to sensitive data from unmanaged devices is blocked, while still allowing access from managed devices. The solution must be implemented using Microsoft Entra ID and Microsoft Intune. You have already deployed Microsoft Intune for mobile device management. What should you do?

Quick Answer

The correct answer is to create a conditional access policy in Microsoft Entra ID that requires the device to be marked as compliant, and apply it to all cloud apps. This works because conditional access acts as the enforcement engine that checks a device’s compliance status—determined by Intune compliance policies—before granting access to sensitive data. Unmanaged devices will fail the compliance check and be blocked, while managed, compliant devices pass through seamlessly. On the MS-102 exam, this scenario tests your understanding of how Intune and Entra ID integrate: Intune defines what “compliant” means, but only conditional access can actually block access based on that status. A common trap is confusing app protection policies (which secure data within apps) with device-level access control, or thinking a compliance policy alone blocks access—it does not. Memory tip: “Compliance defines, Conditional Access enforces.”

⚠ Common exam trap

The trap is confusing app protection policies (which protect data but allow access) with device compliance Conditional Access (which blocks access from non-compliant/unmanaged devices).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a conditional access policy in Microsoft Entra ID that requires device to be marked as compliant, and apply it to all cloud apps.

A Conditional Access policy that requires the device to be marked as compliant enforces that only Intune-managed, compliant devices can access cloud apps. This blocks unmanaged devices because they cannot satisfy the compliance requirement, while managed devices that meet the compliance policy are allowed. This directly satisfies the requirement to block unmanaged device access using Entra ID and Intune.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable device compliance rules in Microsoft Entra ID and assign them to all users.

    Why it's wrong here

    Device compliance rules alone only mark devices compliant or non-compliant; they do not themselves block unmanaged devices, since unmanaged devices simply report as non-compliant without an access control enforcing that state. Compliance policies are tempting because they feed Conditional Access, but a Conditional Access policy granting access only to compliant devices is required.

  • ✗

    Create a device compliance policy in Microsoft Intune that requires a PIN and encryption.

    Why it's wrong here

    A device compliance policy requiring PIN and encryption only evaluates enrolled devices; unmanaged devices are not covered, so they remain unblocked. Compliance policies are tempting because they define device health, but enforcement requires a Conditional Access policy that grants access solely to compliant or managed devices.

  • ✗

    Create an app protection policy in Microsoft Intune that requires managed apps to be used on unmanaged devices.

    Why it's wrong here

    App protection policies govern data within managed apps on enrolled or unmanaged devices, but they do not block access to sensitive documents from unmanaged devices outright. They are tempting because they protect corporate data on BYOD, yet the requirement is to deny unmanaged-device access entirely, which Conditional Access device filters achieve.

  • ✓

    Create a conditional access policy in Microsoft Entra ID that requires device to be marked as compliant, and apply it to all cloud apps.

    Why this is correct

    A conditional access policy requiring compliant devices blocks unmanaged devices while permitting Intune-managed ones, since compliance state is evaluated per device. Applying it to all cloud apps enforces this across Microsoft 365 workloads, satisfying the strict compliance requirement.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MS-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization's Microsoft Intune environment enforces device compliance policies for iOS devices. You need to ensure that only devices with a passcode that is at least 6 characters and have jailbreak detection enabled are considered compliant. What should you configure?

medium
  • A.Configure a conditional access policy to require compliant devices.
  • B.Create a device configuration profile for iOS with the required settings.
  • C.Create an app protection policy for iOS to require passcode.
  • ✓ D.Create a device compliance policy for iOS with required passcode length and jailbreak detection.

Why D: Device compliance policies in Microsoft Intune define the rules that devices must meet to be considered compliant, such as minimum OS version, passcode length, and jailbreak detection. Option D correctly specifies creating a compliance policy for iOS that requires a passcode of at least 6 characters and enables jailbreak detection, which directly enforces the stated requirements. Compliance policies are evaluated before granting access, and non-compliant devices can be blocked or marked for remediation.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.