MD-101 Mobile Application Management and App Protection 2 — Questions and Answers
Question 1: What must users do on an unenrolled iOS device before App Protection Policies take effect in apps like Outlook?
- Enroll the device in Intune
- Sign in with their Azure AD corporate account within the Intune-managed app (Correct answer)
- Install the Intune Company Portal and enroll
- Enable the Intune MAM SDK manually
Correct answer: Sign in with their Azure AD corporate account within the Intune-managed app
On unenrolled devices, App Protection Policies activate when the user signs into the app with their corporate Azure AD account, triggering policy evaluation.
Question 2: Which Intune App Protection Policy conditional launch setting blocks jailbroken or rooted devices from accessing corporate app data?
- Min OS version
- Jailbroken/rooted devices — Block access or Wipe data (Correct answer)
- Min app version
- Disabled account — Block access
Correct answer: Jailbroken/rooted devices — Block access or Wipe data
The 'Jailbroken/rooted devices' conditional launch setting detects compromised devices and can block access or wipe corporate data from the app.
Question 3: An organization deploys Outlook with an App Protection Policy requiring PIN. A user says they are not prompted for a PIN. What is the most likely cause?
- The device is enrolled in MDM and the device-level PIN satisfies the app PIN requirement
- The App Protection Policy is not assigned to the user's Azure AD group (Correct answer)
- Outlook is not supported by App Protection Policies
- The user's device PIN is too short
Correct answer: The App Protection Policy is not assigned to the user's Azure AD group
If the user's group is not included in the App Protection Policy assignment, the policy never applies and no PIN prompt appears.
Question 4: Which Intune report shows the protection status of apps across users, including whether App Protection Policies have been applied?
- App install status report
- App protection status report under Apps > Monitor (Correct answer)
- Device compliance report
- Endpoint analytics — App reliability
Correct answer: App protection status report under Apps > Monitor
The App protection status report under Apps > Monitor in Intune shows per-user and per-app protection policy application status.
Question 5: What is the purpose of the 'Minimum OS version' conditional launch setting in an App Protection Policy?
- To block enrollment of older devices
- To block or warn users on OS versions below the minimum from accessing corporate app data (Correct answer)
- To require an OS update before app installation
- To configure the app's minimum supported SDK version
Correct answer: To block or warn users on OS versions below the minimum from accessing corporate app data
The Minimum OS version conditional launch setting blocks access or warns users when their device OS is below the required version, protecting against known OS vulnerabilities.
Question 6: Which Intune capability allows managed apps to open documents only in other managed apps, preventing data leakage to personal apps?
- App configuration policies
- Managed Open-In / Share extension restriction via App Protection Policy data transfer settings (Correct answer)
- Device restrictions profile
- Conditional Access App Control
Correct answer: Managed Open-In / Share extension restriction via App Protection Policy data transfer settings
App Protection Policy data transfer settings restrict 'Send org data to other apps' to 'Policy managed apps only', enforcing Managed Open-In on iOS and Android.
What must users do on an unenrolled iOS device before App Protection Policies take effect in apps like Outlook?