Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that only compliant devices can access Microsoft 365 resources. What should you configure?

⚠ Common exam trap

A common mix-up: candidates confuse the role of Intune compliance policies (which only define and report compliance) with Conditional Access policies (which enforce access decisions), leading them to select Option B instead of D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a conditional access policy in Microsoft Entra ID requiring compliant devices.

Conditional Access policies in Microsoft Entra ID (formerly Azure AD) are the mechanism that enforces access controls based on signals such as device compliance. By creating a policy that requires compliant devices, you ensure that only devices meeting your compliance standards can access Microsoft 365 resources. This works in conjunction with Intune compliance policies, but the enforcement point is the Conditional Access policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure an app protection policy in Intune.

    Why it's wrong here

    Intune app protection policies (MAM) govern how data is handled within mobile apps—for example, disabling cut/copy/paste, requiring PIN to open an app, or applying encryption. They travel with the app and can apply to enrolled and unenrolled devices alike, but they do not evaluate the device's overall compliance or block sign-in access to services. Access to a resource is not gated by APP; enforcement must occur at the authorization layer such as Conditional Access.

  • ✗

    Create a device compliance policy in Intune.

    Why it's wrong here

    A device compliance policy in Intune defines the rules that determine whether a device is considered compliant, such as OS build minimums, BitLocker encryption, jailbreak detection, and password requirements. It marks a device as Compliant or Noncompliant, but by itself it performs no access decision and denies nothing. To act on that compliance state and block noncompliant devices, you must create a Conditional Access policy that uses the compliance signal as a condition. Therefore compliance alone is not an enforcement mechanism.

  • ✗

    Configure a Windows Hello for Business policy in Intune.

    Why it's wrong here

    Windows Hello for Business configures alternative sign-in credentials using PIN, biometrics, or cryptographic key pairs for users. It replaces traditional passwords and improves the authentication experience, but it does not enforce authorization decisions on resource access. A user could authenticate with Windows Hello and still access noncompliant data; the policy does not assess compliance status and cannot require it. It is an authentication method, not an access-control gate.

  • ✓

    Create a conditional access policy in Microsoft Entra ID requiring compliant devices.

    Why this is correct

    To demand that managed Windows 10 devices be compliant before they access cloud resources, create a Conditional Access policy in Microsoft Entra ID. In the Grant section, select the 'Require device to be marked as compliant' control; this reads the last-known compliance status that Intune reports to Microsoft Entra ID and blocks sign-in if the device is not compliant or is unknown. This grant control works alongside your Intune compliance policies to enforce access decisions at sign-in time. This is the only option listed that actually enforces a device-compliancy requirement.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.