Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Your company uses Microsoft Intune to manage devices. You need to design a solution that prevents users from installing unauthorized applications on corporate Windows 10 devices. Which Intune policy should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Device restriction policy (Windows 10)

A Device restriction policy (Windows 10), because this policy type includes settings that control app installation behavior on Windows 10 devices, such as blocking users from installing apps from untrusted sources or restricting Microsoft Store access. In Intune, device restriction policies are specifically designed to enforce hardware, software, and app-related restrictions on managed devices, making them the appropriate choice for preventing unauthorized application installations. A compliance policy (A) only evaluates and reports device state against conditions and can trigger conditional access, but it does not directly block app installation. An app protection policy (B) applies to mobile app management (MAM) for protecting corporate data within apps, not to blocking installation of unauthorized apps on Windows 10. A configuration policy using OMA-URI (D) can set custom CSP settings, but it is not the purpose-built policy for app installation restrictions that the device restriction policy provides.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Compliance policy

    Why it's wrong here

    Compliance policies evaluate device health against conditions such as minimum OS version, required encryption, and a cleared threat score. A device that fails is marked non-compliant and can be blocked from company resources via Conditional Access, or it can be forcefully removed from management. These policies are purely state-based assessments; they have no enforcement mechanism to prevent a user from launching an installer or to filter untrusted sources during installation. Therefore, a compliance policy cannot satisfy the requirement to block app installation from untrusted sources.

  • ✗

    App protection policy (MAM)

    Why it's wrong here

    App Protection Policies (MAM) govern how data behaves inside specific managed apps—for example, disabling copy/paste, blocking screen capture, requiring a PIN, or preventing 'Save As' to personal space. They apply at the app layer and work even on unenrolled or BYOD devices. MAM has no concept of installation-time validation; it only wraps runtime behavior once a protected app is in use. Because it never evaluates a package's source during setup, it cannot block a user from installing an app from an untrusted location.

  • ✓

    Device restriction policy (Windows 10)

    Why this is correct

    A Windows 10 device restriction profile contains an 'Apps' category with a setting named 'Block installing apps from sources other than Microsoft Store' (the Store-only installation toggle). Setting this to 'Block' enforces the Windows AppRuntime policy that allows or disallows apps based on trusted source. The Intune profile also covers related switches like 'Block all apps from the Microsoft Store,' giving granular control. This is the native, purpose-built mechanism in Microsoft Intune to prevent untrusted app installation.

  • ✗

    Configuration policy (OMA-URI)

    Why it's wrong here

    OMA-URI configuration policies are a custom mechanism that lets you push any Windows Management Infrastructure (SyncML) setting to a device as raw XML. To block untrusted installs, you would have to manually craft a URI such as `./Vendor/MSFT/Policy/Config/AppRuntime/AllowAllTrustedApps` and set it to zero, then maintain it outside the standard UI. That approach is less discoverable, lacks built-in validation, and is easy to misconfigure—it is not the intended 'configuration policy' for app installation control. Intune's dedicated device restriction profile is the correct, supported interface for this enforcement.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.