nerdexam
Microsoft

MD-102 · Question #481

You have a Microsoft 365 subscription that includes Microsoft Intune. You create a new Android app protection policy named Policy1 that prevents screen captures in all Microsoft apps. You discover tha

The correct answer is A. Create a Conditional Access policy.. To restrict email access solely to Microsoft apps on Android devices when an unmanaged email client bypasses an app protection policy, a Conditional Access policy is needed.

Submitted by wei.xz· Apr 18, 2026Protect devices

Question

You have a Microsoft 365 subscription that includes Microsoft Intune. You create a new Android app protection policy named Policy1 that prevents screen captures in all Microsoft apps. You discover that an unmanaged email client installed on Android devices can still capture screens. You need to ensure that users can only use Microsoft apps to access email. What should you do?

Options

  • ACreate a Conditional Access policy.
  • BCreate a compliance policy.
  • CModify the Data protection settings of Policy1.
  • DModify the assignments of Policy1.

How the community answered

(49 responses)
  • A
    55% (27)
  • B
    24% (12)
  • C
    14% (7)
  • D
    6% (3)

Why each option

To restrict email access solely to Microsoft apps on Android devices when an unmanaged email client bypasses an app protection policy, a Conditional Access policy is needed.

ACreate a Conditional Access policy.Correct

Conditional Access policies can be configured to require specific client apps for accessing cloud apps like Exchange Online. By setting a condition to require approved client apps and targeting Exchange Online, users would be blocked from accessing email from any non-Microsoft or unapproved email client.

BCreate a compliance policy.

A compliance policy ensures the device itself meets certain security standards, but it doesn't directly control which apps can access specific cloud services.

CModify the Data protection settings of Policy1.

Modifying data protection settings in Policy1 would only apply to the managed Microsoft apps it already targets, not prevent unmanaged apps from accessing data.

DModify the assignments of Policy1.

Modifying assignments of Policy1 would change who the existing app protection policy applies to, not restrict which apps can access email generally.

Concept tested: Conditional Access for app client control

Source: https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-grant#require-approved-client-app

Topics

#Intune App Protection#Conditional Access#Android#Email Access Control

Community Discussion

No community discussion yet for this question.

Full MD-102 Practice