Courseiva
Deploy and manage a Microsoft 365 tenantmediumMultiple ChoiceObjective-mapped

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Your organization uses Microsoft 365 and wants to ensure that only compliant devices can access Exchange Online. You have Microsoft Intune for device management. What should you configure?

⚠ Common exam trap

Many exam-takers confuse creating a device compliance policy (which only defines rules) with the Conditional Access policy that actually enforces those rules, leading them to select Option D instead of B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a Conditional Access policy with 'Require device to be marked as compliant'

To enforce that only compliant devices can access Exchange Online, you need a Conditional Access policy that includes the 'Require device to be marked as compliant' grant control. This policy evaluates the device compliance status reported by Intune and blocks or grants access accordingly. Without this Conditional Access policy, even compliant devices are not forced to meet compliance requirements before accessing Exchange Online.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure devices to be Azure AD Joined

    Why it's wrong here

    Azure AD Join establishes a device identity in Microsoft Entra ID, enabling single sign-on and management via Intune/MDM. However, join status alone does not include any evaluation of device health, security configuration, or compliance posture. Because access enforcement is handled by Conditional Access, a non-compliant but Azure AD joined device can still authenticate and reach Exchange Online unless a CA policy explicitly checks compliance. Thus, configuring devices to be Azure AD Joined is a prerequisite but not an access-control mechanism.

  • Create a Conditional Access policy with 'Require device to be marked as compliant'

    Why this is correct

    A Conditional Access policy requiring device compliance integrates with Microsoft Intune’s compliance policies to block non-compliant devices from Exchange Online access. This satisfies the stem’s requirement that only compliant devices connect, because Intune evaluates device health (e.g., encryption, jailbreak status) and reports the result to Microsoft Entra ID, which enforces the access grant during authentication.

  • Create an app protection policy in Intune

    Why it's wrong here

    An Intune app protection policy (APP) targets managed applications and restricts actions like copy/paste, save-as, or data transfer to other apps, preventing data leakage from business apps on unmanaged devices. It does not assess the device's overall compliance status, nor does it block connectivity to Exchange Online from a non-compliant device—mail apps not subject to APP can still connect. APP is a data-loss-prevention control applied inside apps, not a network access control, so it cannot be the sole mechanism for ensuring only compliant devices connect.

  • Create a device compliance policy in Intune

    Why it's wrong here

    An Intune device compliance policy defines required conditions such as OS version, disk encryption, and jailbreak detection, and it updates the device's compliance state in Microsoft Entra ID. But the policy itself performs no real-time authorization: it only evaluates and reports. Without an accompanying Conditional Access policy that consumes the compliant state and enforces access grants, non-compliant devices remain able to access Exchange Online. Compliance policy is a signal source, not an enforcement point.

About these practice questions

This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.