2V0-62.23 · Question #73
A company has an organization group (OG) which is only used to register approved devices only. The administrator notices that employees are using that Group ID to register their own devices without…
The correct answer is C. Create an enrollment restriction for the organization group. Creating an enrollment restriction (C) directly controls who or what can register into a specific Organization Group - it's the purpose-built mechanism for gating device enrollment. An enrollment restriction lets the administrator define rules (e.g., allowed platforms…
Question
A company has an organization group (OG) which is only used to register approved devices only. The administrator notices that employees are using that Group ID to register their own devices without authorization. How can the administrator prevent future device registration into this OG?
Options
- APublish a restriction profile to devices in the organization group.
- BCreate a compliance policy preventing unauthorized enrollment.
- CCreate an enrollment restriction for the organization group.
- DMake the Group ID blank for the organization group.
How the community answered
(31 responses)- A6% (2)
- B13% (4)
- C77% (24)
- D3% (1)
Explanation
Creating an enrollment restriction (C) directly controls who or what can register into a specific Organization Group - it's the purpose-built mechanism for gating device enrollment. An enrollment restriction lets the administrator define rules (e.g., allowed platforms, ownership types, or user groups) that must be met before a device can be registered into that OG, blocking unauthorized self-enrollment at the source.
Why the distractors are wrong:
- A - A restriction profile is pushed to already-enrolled devices; it does nothing to prevent new unauthorized enrollments from happening in the first place.
- B - Compliance policies evaluate devices after they are already enrolled and enrolled; they cannot block the enrollment act itself.
- D - Blanking the Group ID would break the OG's functionality entirely and is not a supported or practical security control; it would disrupt legitimate enrollments too.
Memory tip: Think of enrollment restrictions as a bouncer at the door - they decide who gets in before anything else happens. Compliance policies and profiles are rules for people already inside. If the problem is unauthorized entry, you need the bouncer (enrollment restriction), not the house rules (compliance/profiles).
Topics
Community Discussion
No community discussion yet for this question.