MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
Your company uses Microsoft 365 and has recently deployed Microsoft Intune for mobile device management. You need to ensure that corporate data on iOS devices is protected by preventing users from copying data from managed apps to unmanaged apps. What should you configure?
⚠ Common exam trap
Test-takers frequently confuse the deployment model (MAM without enrollment) with the actual policy configuration (app protection policies), or they mistakenly think device compliance or Conditional Access can control app-level data sharing, which they cannot.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
App protection policies.
App protection policies (APP) are the correct choice because they provide mobile application management (MAM) controls that specifically prevent data transfer between managed and unmanaged apps on iOS devices. Unlike device-level policies, APP operates at the application layer, allowing you to restrict copy/paste, cut, and data sharing actions without requiring device enrollment. This directly addresses the requirement to protect corporate data on iOS devices by blocking data leakage to unmanaged apps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mobile application management (MAM) without enrollment.
Why it's wrong here
MAM without enrollment is a deployment model that lets you apply app protection policies to devices that are not enrolled in Microsoft Intune MDM. However, this model does not itself define the data-transfer restrictions; those restrictions are configured inside an app protection policy. Because the question asks which mechanism contains the setting to restrict copy-paste, choosing MAM without enrollment confuses the delivery channel with the actual policy definition.
- ✗
Device compliance policies.
Why it's wrong here
Device compliance policies evaluate device-level conditions such as operating system versions, jailbreak status, and encryption to determine whether a device meets security baselines. These policies do not contain any app-specific settings that govern clipboard behavior or inter-app data sharing. Even if a device is fully compliant, a user could still copy-paste data from a managed app into an unmanaged app unless a separate app protection policy restricts that action.
- ✗
Conditional Access policies.
Why it's wrong here
Conditional Access policies operate at the authentication gate and use signals like user identity, location, device compliance, and sign-in risk to grant or block access to Microsoft 365 services. They are evaluated before any app functionality is available, and they cannot enforce granular controls on how data is handled inside an application. Restricting copy-paste requires an app-level policy that remains active on the device after access is granted.
- ✓
App protection policies.
Why this is correct
App protection policies in Microsoft Intune are specifically designed to manage data protection at the application layer, including settings to prevent copy-paste of organizational data into unmanaged apps. These policies can be assigned directly to users across devices with or without MDM enrollment, making them the correct mechanism for this scenario. For example, the 'Restrict cut, copy, and paste' policy mode can block the action entirely or allow it only between managed apps.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Mobile application management
Mobile application management (MAM) is the practice of controlling and securing corporate apps and their data on employee-owned or company-provided mobile devices without managing the entire device.
Key term
Mobile device management
Mobile device management (MDM) is a security solution that allows IT administrators to enroll, configure, monitor, and enforce policies on smartphones, tablets, and other mobile devices used in an organization.
About these practice questions
Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.