MD-102 - Prepare Infrastructure for Devices (23% of the exam) - Section 1.3

Implement identity and compliance for devices, including Intune roles, compliance policies and Conditional Access.

Manage built-in and custom roles for Intune and Windows 365, scope tags for multi-admin environments, and multi-admin approval. Implement device compliance policies for every supported platform and Microsoft Entra Conditional Access policies that require a compliant device, then configure Windows Hello for Business, Windows LAPS, and local group membership on Windows devices by using Intune.

Intune role-based access controlscope tagsmulti-admin approvaldevice compliance policiesConditional Access require compliant deviceWindows Hello for BusinessWindows LAPS

Practice question for this objective

Free samplePrepare Infrastructure for Devicesmedium

Members of staff use personally owned Windows 11 laptops that are Microsoft Entra registered, and they sign in to Microsoft 365 with a work account. A Windows compliance policy in Microsoft Intune already states a minimum operating system build and requires BitLocker, and a Conditional Access policy requiring a compliant device is ready to be switched on. The registered laptops currently report no compliance state whatsoever. What has to be in place before that compliance policy can report a state for them?

  • AThe compliance policy has to be assigned to a dynamic device group whose rule selects registered devices, because a policy assigned to a user group is never evaluated on a personally owned laptop.
  • BThe Conditional Access grant has to be changed to require a Microsoft Entra hybrid joined device, because a personally owned laptop is unable to report a compliance state under any configuration.
  • CThe laptops have to be enrolled in Microsoft Intune, because registration creates a device identity while a compliance state is produced by a managed device evaluating a policy assigned to it. Correct
  • DThe laptops have to be moved from Microsoft Entra registered to Microsoft Entra joined, because a compliance policy in Microsoft Intune evaluates only devices that are joined to the tenant.
Microsoft Entra registration gives a device an identity for Conditional Access, but a compliance state exists only once the device is enrolled in Microsoft Intune. Device registration and device management answer different questions. Registration records that a device belongs to a user in the tenant and gives Conditional Access something to evaluate, whereas a compliance policy is delivered to a device by Microsoft Intune and evaluated by the management client on that device. Until the registered laptops are enrolled, nothing on them reads the policy, so the absent compliance state is expected rather than a fault in the policy or its assignment.

Why A is wrong: Tempting because targeting is a common cause of a policy not applying, but compliance policies can be assigned to user groups as well as device groups, and no assignment reaches a device that Intune does not manage.

Why B is wrong: Wrong because a personally owned laptop can be enrolled and can report compliance, and requiring the hybrid joined state would refuse these laptops outright rather than let them meet the stated requirements.

Why C is correct: Correct because a compliance policy is delivered to and evaluated on a device that Intune manages, so a registered but unenrolled laptop has an identity in the directory and nothing reporting against the policy.

Why D is wrong: Tempting because joining is the corporate pattern, but compliance evaluation depends on Intune enrolment rather than on the join type, and joining a personally owned laptop changes how its owner signs in to Windows.

See more MD-102 practice questions, answers explained.

Exam traps in Prepare Infrastructure for Devices

Answers that look right on this material and are not. Each one is a distractor from a different question in the MD-102 bank for this domain.

  • Add the macOS devices to the assignment of the existing Windows compliance policy so that policy evaluates them.

    Why it is wrong: Widening an assignment feels like the quickest route, but a compliance policy is authored against one platform and its settings have no meaning on another. The Macs would still fall through as unevaluated.

  • Microsoft Defender for Endpoint, which reports a device threat level that an Intune compliance policy can consume as a compliance rule.

    Why it is wrong: Defender genuinely feeds a device threat level into a compliance policy setting, which makes it plausible here, but that signal is optional and it neither enrols the device nor brokers the sign-in.

  • Set the tenant wide Windows Hello for Business setting to enabled with a six digit PIN, then assign a device configuration profile to the other devices to switch it back off.

    Why it is wrong: Tempting because it does produce a working pilot, but it inverts the requirement: the tenant wide setting applies at enrolment for every Windows device, so this turns the feature on broadly and relies on a second policy to undo it.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.