MD-101 Conditional Access and Compliance Policies 2 — Questions and Answers
Question 1: Which Intune compliance setting verifies that Windows devices have Microsoft Defender Antivirus real-time protection enabled?
- Require BitLocker
- Require Windows Defender ATP device risk score
- Microsoft Defender Antivirus — Require real-time protection (Correct answer)
- Secure boot required
Correct answer: Microsoft Defender Antivirus — Require real-time protection
The 'Require real-time protection' setting in Intune compliance policies checks that Microsoft Defender Antivirus real-time protection is active.
Question 2: What is the purpose of a Conditional Access Named Location in access policies?
- To name Conditional Access policies for reporting purposes
- To define trusted IP ranges or countries for use in access conditions (Correct answer)
- To name Azure AD groups used in CA policies
- To label compliant device groups
Correct answer: To define trusted IP ranges or countries for use in access conditions
Named Locations define trusted IP address ranges or geographic regions that can be used as conditions in Conditional Access policies.
Question 3: An administrator wants to require Intune-enrolled devices for access to SharePoint but allow personal devices with MFA only. Which Conditional Access grant configuration achieves this?
- Require compliant device AND require MFA
- Require compliant device OR require MFA (Correct answer)
- Require compliant device only
- Block all access without MFA
Correct answer: Require compliant device OR require MFA
Using 'Require one of the selected controls' with both 'Require compliant device' and 'Require MFA' allows either condition to satisfy the grant requirement.
Question 4: Which Azure AD Conditional Access signal can assess device risk using Microsoft Defender for Endpoint threat intelligence?
- User risk (Identity Protection)
- Device risk via Microsoft Defender for Endpoint integration (Correct answer)
- Sign-in risk
- Insider risk management signal
Correct answer: Device risk via Microsoft Defender for Endpoint integration
Conditional Access can use the device risk score from Microsoft Defender for Endpoint as a condition, blocking access when device threat level is too high.
Question 5: What happens to a device's compliance status if it has been offline and has not checked in with Intune beyond the configured inactivity period?
- It remains compliant indefinitely
- It is marked Not compliant (Correct answer)
- It is automatically wiped
- It is moved to a quarantine group
Correct answer: It is marked Not compliant
Intune marks devices as Not compliant if they exceed the configured 'Days without checking in' threshold, which administrators set in compliance policy settings.
Question 6: Which report in Intune provides a consolidated view of device compliance status across all platforms?
- Device enrollment report
- Endpoint analytics — Device performance
- Compliance — Monitor > Device compliance report (Correct answer)
- Azure AD — Devices > All devices
Correct answer: Compliance — Monitor > Device compliance report
The Device compliance report under Compliance > Monitor in Intune shows aggregate and per-device compliance status across all enrolled platforms.
Which Intune compliance setting verifies that Windows devices have Microsoft Defender Antivirus real-time protection enabled?