Exam objective

MD-102

Implement identity and compliance

This objective sits in Prepare infrastructure for devices, which carries 23% of the MD-102 Endpoint Administrator exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Prepare infrastructure for devices

Your tenant uses Conditional Access to require compliant devices. How should you set 'Mark devices with no compliance policy assigned as'?

CompliantCompliant (the default) would let unassigned devices through.
Not compliantCorrect · your answerCorrect.
UnknownUnknown is not a value for this setting.
QuarantinedQuarantined is a per-platform enforcement state, not this setting.

Correct.

Concept

This tenant-wide setting decides how devices without an assigned policy are treated. When Conditional Access gates on compliance, unassigned devices should not be trusted by default.

Why B

Set it to Not compliant so only confirmed-compliant devices can access resources.

Source

If you use Conditional Access with your device compliance policies, change this setting to Not compliant to ensure that only devices that are confirmed as compliant can access your resources.

Microsoft, Device compliance policies in Microsoft Intune, checked August 2026
#identity-compliance

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Prepare infrastructure for devices

On a Microsoft Entra hybrid joined device, when can a user first sign in with a newly provisioned Windows Hello for Business cloud Kerberos trust PIN?

Sample question 2 of 3

Prepare infrastructure for devices

A managed device fails a compliance rule. By default, what action does every Intune device compliance policy take?

Sample question 3 of 3

Prepare infrastructure for devices

You deploy Windows Hello for Business with cloud Kerberos trust, but a certificate-for-on-premises-authentication policy is also enabled. What is the effect?

That’s 3 of the full MD-102 Endpoint Administrator bank.

Keep going free: 10 questions per certification in bank practice, with no account.

Continue practising

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Prepare infrastructure for devices