nerdexam
Microsoft

MD-102 · Question #403

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…

The correct answer is B. No. The answer is No. The scenario involves a Conditional Access policy targeting User1 with a cloud app assignment. Based on the truncated policy settings (which typically include a 'compliant device' or 'approved app' grant control), at least one of User1's devices (Device1 or…

Submitted by luis.pe· Apr 18, 2026Protect devices

Question

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 E5 subscription that contains a user named User1 and the devices shown in the following table. User1 can access her Microsoft Exchange Online mailbox from both Device1 and Device2. You plan to create a Conditional Access policy named CAPolicy1 that will have the following settings:

  • Assignments
  • Users or workload identities: User1
  • Cloud apps or actions: Office 365 Exchange Online
  • Access controls
  • Grant: Block access

You need to configure CAPolicy1 to allow mailbox access from Device1 but block mailbox access from Device2. Solution: You add a condition that specifies device platforms. Does this meet the goal?

Exhibit

MD-102 question #403 exhibit

Options

  • AYes
  • BNo

How the community answered

(24 responses)
  • A
    46% (11)
  • B
    54% (13)

Explanation

The answer is No. The scenario involves a Conditional Access policy targeting User1 with a cloud app assignment. Based on the truncated policy settings (which typically include a 'compliant device' or 'approved app' grant control), at least one of User1's devices (Device1 or Device2) does not satisfy the compliance or platform requirement defined in the policy. Because the policy cannot enforce the intended control across both devices as described, the goal is not achieved.

Topics

#Conditional Access#Exchange Online#Device filtering#Entra ID

Community Discussion

No community discussion yet for this question.

Full MD-102 Practice