MD-101 Conditional Access and Compliance Policies 1 — Questions and Answers
Question 1: What is the first thing Intune evaluates when a device checks in for compliance assessment?
- Whether the user has a valid Intune license
- Whether any compliance policies are assigned to the device or user (Correct answer)
- Whether the device has internet connectivity
- Whether BitLocker is enabled
Correct answer: Whether any compliance policies are assigned to the device or user
Intune first checks if any compliance policies are assigned; devices with no compliance policy are considered compliant by default unless the tenant setting is changed.
Question 2: Which Azure AD feature integrates with Intune compliance status to block non-compliant devices from accessing corporate resources?
- Azure AD Identity Protection
- Conditional Access requiring a compliant device (Correct answer)
- Privileged Identity Management
- Azure AD Access Reviews
Correct answer: Conditional Access requiring a compliant device
Conditional Access can require 'device marked as compliant' as a grant control, blocking access to apps until the device meets Intune compliance requirements.
Question 3: An Intune compliance policy sets minimum OS version to Windows 10 21H2. A device running 21H1 is enrolled. What is the device's compliance state?
- Compliant
- Not compliant (Correct answer)
- In grace period
- Not evaluated
Correct answer: Not compliant
A device running an OS version lower than the required minimum is immediately marked Not compliant by the Intune compliance policy.
Question 4: What does the Intune compliance policy 'grace period' setting control?
- How long a device can remain offline before being marked non-compliant
- The number of days a non-compliant device retains access before Conditional Access blocks it (Correct answer)
- How long a user has to enroll their device after joining Azure AD
- The time between compliance evaluation cycles
Correct answer: The number of days a non-compliant device retains access before Conditional Access blocks it
The grace period gives users a defined number of days to remediate non-compliance before Conditional Access enforces the block, preventing immediate access disruption.
Question 5: Which compliance policy action sends an automatic notification email to users when their device becomes non-compliant?
- Mark device non-compliant
- Send email to end user — under Actions for noncompliance (Correct answer)
- Retire device
- Lock remote device
Correct answer: Send email to end user — under Actions for noncompliance
The 'Send email to end user' action in compliance policy Actions for noncompliance automatically notifies users with configurable message templates.
Question 6: A Conditional Access policy requires MFA for all users accessing Exchange Online. A user with a compliant Intune device still gets prompted for MFA. What is the likely cause?
- Intune compliance grants bypass all Conditional Access controls
- The Conditional Access policy requires both MFA and compliant device — both controls must be satisfied (Correct answer)
- The user's device is not Azure AD joined
- MFA is only required for non-compliant devices
Correct answer: The Conditional Access policy requires both MFA and compliant device — both controls must be satisfied
When Conditional Access requires multiple grant controls with 'Require all selected controls', users must satisfy all requirements including MFA even if device is compliant.
What is the first thing Intune evaluates when a device checks in for compliance assessment?