Microsoft 365 Endpoint Administrator Associate MD-102 Practice Question

You deploy a Conditional Access policy in Microsoft Entra ID that grants access to Microsoft 365 resources only to devices marked as compliant. No Windows compliance policies have been assigned yet. As a result, newly enrolled Windows 11 laptops without BitLocker are still able to connect to Exchange Online. You must ensure that a device that has not been evaluated against any compliance policy is blocked until it is found compliant. Which Intune action should you perform first?

  • Configure the compliance policy setting "Mark devices with no compliance policy assigned as" to Not compliant.

  • Switch the Conditional Access policy from Report-only to On.

  • Enable a global tenant setting named Require device compliance for Conditional Access.

  • Change the grant control in the Conditional Access policy to Require Hybrid Azure AD-joined device.

Microsoft 365 Endpoint Administrator Associate MD-102
Prepare infrastructure for devices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot