Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Your organization's Microsoft Intune environment enforces device compliance policies for iOS devices. You need to ensure that only devices with a passcode that is at least 6 characters and have jailbreak detection enabled are considered compliant. What should you configure?

⚠ Common exam trap

It's easy for candidates to confuse device compliance policies (which enforce device-level security requirements) with conditional access policies (which use compliance results to control access) or device configuration profiles (which push settings but do not evaluate compliance).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a device compliance policy for iOS with required passcode length and jailbreak detection.

Device compliance policies in Microsoft Intune define the rules that devices must meet to be considered compliant, such as minimum OS version, passcode length, and jailbreak detection. Option D correctly specifies creating a compliance policy for iOS that requires a passcode of at least 6 characters and enables jailbreak detection, which directly enforces the stated requirements. Compliance policies are evaluated before granting access, and non-compliant devices can be blocked or marked for remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a conditional access policy to require compliant devices.

    Why it's wrong here

    A conditional access policy is an enforcement gate, not a definition of compliance. It evaluates signals like device compliance status, which must already be established by a separate compliance policy. If no compliance policy exists, the device is never marked compliant, so this approach fails to define the passcode and jailbreak requirements. Conditional access simply blocks or allows access based on that precomputed state.

  • ✗

    Create a device configuration profile for iOS with the required settings.

    Why it's wrong here

    A device configuration profile is used to deliver settings and features to devices, such as restrictions, Wi-Fi, or email settings. It does not evaluate whether a device meets security requirements like passcode length or jailbreak status, nor does it generate a compliance state for conditional access. Configuration profiles are about applying settings, whereas compliance policies are about assessing and enforcing security posture against defined rules.

  • ✗

    Create an app protection policy for iOS to require passcode.

    Why it's wrong here

    App protection policies (APP) operate at the application layer, protecting corporate data within managed apps and enforcing app-level passcode requirements, if configured. They do not assess device-level attributes like jailbreak detection or device passcode length, and they cannot mark a device as compliant or noncompliant. For device-level compliance reporting and conditional access gating, you need a device compliance policy, not an app-level policy.

  • ✓

    Create a device compliance policy for iOS with required passcode length and jailbreak detection.

    Why this is correct

    A device compliance policy in Microsoft Intune is specifically designed to define the rules and settings that devices must meet to be considered compliant. By configuring passcode length and jailbreak detection for iOS, the policy evaluates these conditions and reports a compliant or noncompliant status. This compliance state can then be consumed by conditional access policies to enforce access controls. Therefore, this is the correct mechanism to define the required security conditions.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.