MD-102 · Question #34
Your company has a Microsoft 365 subscription. The company uses Microsoft Intune to manage all devices. The company uses conditional access to restrict access to Microsoft 365 services for devices…
The correct answer is C. The Device compliance blade in the Intune admin center. Option C is correct because the Device compliance blade in the Intune admin center is specifically designed to show the compliance status of all managed devices - it lets you directly see which devices are marked non-compliant and would therefore be blocked by conditional…
Question
Your company has a Microsoft 365 subscription. The company uses Microsoft Intune to manage all devices. The company uses conditional access to restrict access to Microsoft 365 services for devices that do not comply with the company's security policies. You need to identify which devices will be prevented from accessing Microsoft 365 services. What should you use?
Options
- AThe Device Health solution in Windows Analytics.
- BWindows Defender Security Center.
- CThe Device compliance blade in the Intune admin center.
- DThe Conditional access blade in the Azure Active Directory admin center.
How the community answered
(15 responses)- A7% (1)
- B13% (2)
- C73% (11)
- D7% (1)
Explanation
Option C is correct because the Device compliance blade in the Intune admin center is specifically designed to show the compliance status of all managed devices - it lets you directly see which devices are marked non-compliant and would therefore be blocked by conditional access policies.
Why the distractors are wrong:
- A (Windows Analytics / Device Health) - This solution focuses on device health telemetry (upgrade readiness, update compliance), not on Intune compliance policy enforcement.
- B (Windows Defender Security Center) - This is an endpoint security tool for threat protection and antivirus status, not a place to audit Intune compliance policy results.
- D (Conditional Access blade in Azure AD) - While this is where you configure conditional access policies, it does not give you a per-device compliance report showing which devices are currently blocked; that visibility lives in Intune.
Memory tip: Think "Intune manages devices, so Intune reports on devices." If you need to know the compliance state of devices (and therefore who gets blocked), go to the source - the Intune Device compliance blade, not the policy configuration blade in Azure AD.
Topics
Community Discussion
No community discussion yet for this question.