nerdexam
Microsoft

MD-102 · Question #258

You have a Microsoft 365 tenant that contains the devices shown in the following table. The devices are managed by using Microsoft Intune. You create a compliance policy named Policy1 and assign Polic

The correct answer is B. From Device compliance, configure the Compliance policy settings.. In Microsoft Intune, by default, devices that have no compliance policy assigned are considered Compliant. To change this behavior, you must navigate to Device compliance > Compliance policy settings and set the 'Mark devices with no compliance policy assigned as' option to 'Not

Submitted by valeria.br· Apr 18, 2026Manage and maintain devices

Question

You have a Microsoft 365 tenant that contains the devices shown in the following table. The devices are managed by using Microsoft Intune. You create a compliance policy named Policy1 and assign Policy1 to Group1. Policy1 is configured to mark a device as Compliant only if the device security settings match the settings specified in the policy. You discover that devices that are not members of Group1 are shown as Compliant. You need to ensure that only devices that are assigned a compliance policy can be shown as Compliant. All other devices must be shown as Not compliant. What should you do?

Options

  • AFrom Endpoint security, configure the Conditional access settings.
  • BFrom Device compliance, configure the Compliance policy settings.
  • CFrom Policy1, modify the actions for noncompliance.
  • DFrom Tenant administration, modify the Diagnostic settings.

How the community answered

(42 responses)
  • A
    5% (2)
  • B
    81% (34)
  • C
    5% (2)
  • D
    10% (4)

Explanation

In Microsoft Intune, by default, devices that have no compliance policy assigned are considered Compliant. To change this behavior, you must navigate to Device compliance > Compliance policy settings and set the 'Mark devices with no compliance policy assigned as' option to 'Not compliant.' This is a tenant-wide setting that governs how Intune treats unevaluated devices. Option A (Conditional Access) enforces access controls but does not change compliance status. Option C (actions for noncompliance) defines what happens after a device is already marked noncompliant. Option D (Diagnostic settings) deals with log routing, not compliance evaluation logic.

Topics

#Intune compliance policy#Device compliance settings#Default compliance state#Policy assignment

Community Discussion

No community discussion yet for this question.

Full MD-102 Practice