nerdexam
Microsoft

MS-900 · Question #59

You are the Microsoft 365 administrator for a company. All staff must use Microsoft Outlook to access corporate email. When users access Outlook on mobile devices, they must use a PIN to open the appl

The correct answer is C. app protection. This question tests knowledge of which Intune policy type enforces app-level security controls like PIN requirements without requiring device enrollment.

Submitted by javi_es· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

You are the Microsoft 365 administrator for a company. All staff must use Microsoft Outlook to access corporate email. When users access Outlook on mobile devices, they must use a PIN to open the application. You need to implement a Microsoft Intune policy to enforce the security requirements. Which policy should you use?

Options

  • Adevice compliance
  • Bdevice configuration
  • Capp protection
  • Dapp configuration

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    16% (4)
  • C
    72% (18)
  • D
    4% (1)

Why each option

This question tests knowledge of which Intune policy type enforces app-level security controls like PIN requirements without requiring device enrollment.

Adevice compliance

Device compliance policies define rules that a device must meet (e.g., OS version, encryption) to be considered compliant, but they do not enforce app-level controls like requiring a PIN to open a specific application.

Bdevice configuration

Device configuration policies manage device-level settings such as Wi-Fi profiles, VPN, and restrictions, but they do not provide app-specific access controls like enforcing a PIN to launch Outlook.

Capp protectionCorrect

App Protection Policies (APP) in Microsoft Intune allow administrators to enforce access requirements at the application level, such as requiring a PIN to open a specific app like Outlook, regardless of whether the device is enrolled in MDM. This policy targets the app itself rather than the device, making it the correct choice for enforcing a PIN specifically when opening Outlook on mobile devices.

Dapp configuration

App configuration policies deliver configuration settings (e.g., server URLs, account settings) to managed apps, but they are not designed to enforce security requirements like requiring a PIN to open an application.

Concept tested: Intune App Protection Policy PIN enforcement

Source: https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy

Topics

#Intune#App Protection policies#mobile device management#BYOD security

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice