Exam objective
MD-102Plan and implement app protection and app configuration policies
This objective sits in Manage and secure applications, which carries 17% of the MD-102 Endpoint Administrator exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.
Objective title verbatim from the official objectives. Microsoft Azure exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
You must protect corporate data in Office mobile apps on unenrolled personal phones. Which capability fits?
Correct.
Concept
App protection policies secure data at the app layer without requiring enrollment. This suits BYOD where MDM is not used.
Why B
App protection policies can be used independent of any MDM solution, protecting data on unenrolled devices.
Source
Microsoft, App Protection Policies Overview, checked August 2026You can use Intune app protection policies independent of any mobile-device management (MDM) solution. This independence helps you protect your company's data with or without enrolling devices.
Now you: practice questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
On Android, what is required on the device to receive app protection policies?
Sample question 2 of 3
You want a baseline MAM policy for all tenant users through the OneDrive admin center. What kind of policy does that create?
Sample question 3 of 3
A standard targeted app protection policy and the Global policy both apply to a user. Which wins?
That’s 3 of the full MD-102 Endpoint Administrator bank.
Keep going free: 10 questions per certification in bank practice, with no account.
Continue practisingRead the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.