An organisation holds the Intune Suite add-on capabilities and runs a Microsoft Tunnel Gateway server that reports healthy in the Microsoft Intune admin center. Contractors use personally owned iPhones that the organisation has agreed will stay unenrolled, and the work applications on those handsets must reach an internal web application through the tunnel. Select TWO actions that deliver the tunnel client and its connection settings to those handsets.
- ADeploy the Microsoft Defender for Endpoint application to the contractor group as the tunnel client that the handsets will use. Correct
- BCreate an iOS/iPadOS VPN device configuration profile that names the tunnel site, enables per-app VPN and is assigned to the contractor group.
- CCreate an app configuration policy for managed applications that carries the tunnel connection settings, assigned to the contractor group. Correct
- DCreate an iOS compliance policy that requires the tunnel client application, assigned to the contractor group so the handsets report a tunnel state.
- ECreate an enrolment restriction that permits personally owned iOS devices, assigned to the contractor group so the handsets can obtain the tunnel.
Why A is correct: Microsoft Tunnel for Mobile Application Management carries traffic through the Microsoft Defender for Endpoint application acting as the tunnel client, so that application has to reach the handsets before any connection is possible.
Why B is wrong: This is how an enrolled iPhone is given a tunnel connection, which makes it tempting, but a device configuration profile is delivered over the mobile device management channel and an unenrolled handset has no such channel to receive it.
Why C is correct: An app configuration policy targeted at managed applications is delivered through the application protection channel rather than through enrolment, so it is the surface that supplies the tunnel site and server details to the client application on an unenrolled handset.
Why D is wrong: A compliance policy is attractive because it appears to make the client mandatory, but a compliance policy evaluates and reports a state on enrolled devices and configures nothing, so it neither installs the client nor supplies connection settings.
Why E is wrong: An enrolment restriction sounds relevant because it governs personally owned Apple devices, but it decides which devices are allowed to enrol at all and the requirement here is to leave the handsets unenrolled.