MD-102 · Question #84
Your company implements Microsoft Azure Active Directory (Azure AD), Microsoft 365, Microsoft Intune, and Azure Information Protection. The company's security policy states the following: - Personal d
The correct answer is C. an app protection policy from the Intune admin center. By implementing app-level policies, you can restrict access to company resources and keep data within the purview of your IT department. Note: The important benefits of using App protection policies are the following: Protecting your company data at the app level. Because mobile
Question
Your company implements Microsoft Azure Active Directory (Azure AD), Microsoft 365, Microsoft Intune, and Azure Information Protection. The company's security policy states the following:
- Personal devices do not need to be enrolled in Intune.
- Users must authenticate by using a PIN before they can access
corporate email data.
- Users can use their personal iOS and Android devices to access
corporate cloud services.
- Users must be prevented from copying corporate email data to a cloud
storage service other than Microsoft OneDrive for Business. You need to configure a solution to enforce the security policy. What should you create?
Options
- Aa data loss prevention (DLP) policy from the Security & Compliance admin center
- Ba supervision policy from the Security & Compliance admin center
- Can app protection policy from the Intune admin center
- Da device configuration profile from the Intune admin center
How the community answered
(24 responses)- A13% (3)
- B8% (2)
- C50% (12)
- D29% (7)
Explanation
By implementing app-level policies, you can restrict access to company resources and keep data within the purview of your IT department. Note: The important benefits of using App protection policies are the following: Protecting your company data at the app level. Because mobile app management doesn't require device management, you can protect company data on both managed and unmanaged devices. The management is centered on the user identity, which removes the requirement for device End-user productivity isn't affected and policies don't apply when using the app in a personal context. The policies are applied only in a work context, which gives you the ability to protect company data without touching personal data. App protection policies makes sure that the app-layer protections are in place. For example, you Require a PIN to open an app in a work context Control the sharing of data between apps Prevent the saving of company app data to a personal storage location MDM, in addition to MAM, makes sure that the device is protected. For example, you can require a PIN to access the device, or you can deploy managed apps to the device. You can also deploy apps to devices through your MDM solution, to give you more control over app management. https://docs.microsoft.com/en-us/intune/app-protection-policy
Topics
Community Discussion
No community discussion yet for this question.