nerdexam
Microsoft

MD-102 · Question #282

You have a Microsoft 365 E5 subscription that contains the groups shown in the following table. You create a Conditional Access policy named CAPolicy1 that will block access to Microsoft Exchange Onli

The correct answer is D. Add a condition in CAPolicy1 to filter for devices.. To enforce a Conditional Access policy that blocks access from iOS devices, the policy's conditions must explicitly target iOS platforms.

Submitted by yuriko_h· Apr 18, 2026Protect devices

Question

You have a Microsoft 365 E5 subscription that contains the groups shown in the following table. You create a Conditional Access policy named CAPolicy1 that will block access to Microsoft Exchange Online from iOS devices. You assign CAPolicy1 to Group1. You discover that User1 can still connect to Exchange Online from an iOS device. You need to ensure that CAPolicy1 is enforced. What should you do?

Exhibit

MD-102 question #282 exhibit

Options

  • AConfigure a new terms of use (TOU).
  • BAssign CAPolicy1 to Group2.
  • CEnable CAPolicy1.
  • DAdd a condition in CAPolicy1 to filter for devices.

How the community answered

(37 responses)
  • A
    8% (3)
  • B
    19% (7)
  • C
    5% (2)
  • D
    68% (25)

Why each option

To enforce a Conditional Access policy that blocks access from iOS devices, the policy's conditions must explicitly target iOS platforms.

AConfigure a new terms of use (TOU).

Configuring a new terms of use (TOU) is unrelated to blocking access based on device platform in a Conditional Access policy.

BAssign CAPolicy1 to Group2.

Assigning CAPolicy1 to Group2 would only affect users in Group2; if User1 is in Group1, assigning to Group2 does not resolve the enforcement issue for User1.

CEnable CAPolicy1.

While a policy must be enabled to be enforced, the problem states the policy 'will block access... from iOS devices,' implying the specific condition for iOS devices might be missing or misconfigured within the policy despite its description, rather than the entire policy being off.

DAdd a condition in CAPolicy1 to filter for devices.Correct

Even if the policy is named to block iOS devices, its actual configuration within the 'Conditions' section for 'Device platforms' must explicitly include iOS to be enforced for those devices.

Concept tested: Conditional Access policy device platform conditions

Source: https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-conditions#device-platforms

Topics

#Conditional Access#Device filtering#Exchange Online#iOS

Community Discussion

No community discussion yet for this question.

Full MD-102 Practice