MD-102 - Manage and Secure Applications (18% of the exam) - Section 4.2

Plan and implement app protection and app configuration policies.

Plan and implement app protection policies for managed and unmanaged (BYOD) devices, and Microsoft Entra Conditional Access policies that require an app protection policy. Distinguish app configuration policies for managed apps from those for managed devices and choose the right one for a scenario.

app protection policiesMAM without enrollmentConditional Access require app protection policyapp configuration policiesmanaged apps versus managed devices

Practice question for this objective

Free sampleManage and Secure Applicationshard

A firm targets an Intune app protection policy at all of its staff for Outlook on iOS and Android, and the policy blocks the copying of corporate data into applications that Intune does not manage. No Conditional Access policy in the tenant names app protection as a grant control. Which statement correctly describes the boundary of what the app protection policy achieves on its own?

  • AIt refuses a sign-in from any mail application other than Outlook, because Microsoft Intune registers each protected application with Microsoft Entra ID and the identity platform then rejects the applications that are absent from that registration.
  • BIt takes effect once the handset has been enrolled in Microsoft Intune, so an unenrolled handset carries no protection of any kind until a Conditional Access policy has driven its owner through enrolment during a sign-in.
  • CIt governs how corporate data is handled inside Outlook for the users it targets, and nothing in it stops one of those users reaching the same mailbox from a mail application that no app protection policy governs, which is the gap a Conditional Access grant requiring app protection closes. Correct
  • DIt is enforced by Exchange Online at the protocol level, so a mail application that no policy governs is refused by the service itself rather than by the application, and the mailbox therefore stays out of reach of that client.
An app protection policy governs data inside a managed app, while a Conditional Access grant is what refuses access from an app that no policy governs. An app protection policy is enforced by the managed application itself, deciding what may be done with corporate data once that data is inside the application. It says nothing about which client may obtain a token in the first place, so a user targeted by the policy can still add the same mailbox to a mail client that carries no policy and work outside those controls. Conditional Access is the gate that closes this, because its grant requiring an app protection policy refuses a sign-in from a client that is not policy protected, which is why the two features are planned together rather than separately.

Why A is wrong: Tempting because the set of applications that support app protection does feel like an approved list that something must be enforcing at sign-in. It is wrong because Intune does not turn that support into a sign-in restriction, and a Conditional Access grant is what refuses a token to a client that is not policy protected.

Why B is wrong: Tempting because much of Intune does depend on an enrolment record, and candidates often assume every Intune control does. It is wrong because app protection policies apply to managed applications without enrolment, which is the arrangement usually described as MAM without enrolment.

Why C is correct: Correct because an app protection policy is a data handling control applied inside a managed application, and it has no say over which client the identity platform will issue a token to, so the choice of client stays open until a Conditional Access grant constrains it.

Why D is wrong: Tempting because mailbox level controls that act on client protocols do exist and produce a superficially similar outcome. It is wrong because an app protection policy is delivered to and enforced by the managed application on the handset, and it places no restriction inside the mail service.

See more MD-102 practice questions, answers explained.

Exam traps in Manage and Secure Applications

Answers that look right on this material and are not. Each one is a distractor from a different question in the MD-102 bank for this domain.

  • A policy for managed devices carries configuration values to enrolled and unenrolled handsets alike, while a policy for managed apps carries values only to applications the organisation has written and published itself.

    Why it is wrong: Tempting because the managed devices channel is the one most administrators meet first and feels like the general case. It is wrong in both halves: that channel needs an enrolment record, and the managed apps channel is not restricted to in-house applications.

  • Enrol the contractor iPhones in Microsoft Intune with the Company Portal app, so that each handset carries an enrolment record the Conditional Access grant control can evaluate at sign-in.

    Why it is wrong: Enrolment is tempting because it is the familiar route to managing a handset, but the organisation has agreed the handsets stay unenrolled, and the grant control in question evaluates the app protection state of the client application rather than an enrolment record.

  • Create a second app configuration policy with the device enrolment type set to managed devices and assign it to a group holding the contractor user accounts.

    Why it is wrong: Tempting because a second policy looks like a scoping fix, but the managed devices enrolment type delivers configuration through the device management channel, so an unenrolled handset has no channel to receive it and the result is unchanged.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.