Microsoft 365 FundamentalsDescribe core Microsoft 365 services and conceptsMedium

A Microsoft 365 administrator wants to ensure that all user devices connected to the corporate network comply with security policies, such as requiring a minimum operating system version and enforcing encryption. Which Microsoft 365 service should be used to manage and enforce these device compliance policies?

  1. AMicrosoft Information Protection
  2. BMicrosoft Defender for Cloud Apps
  3. CMicrosoft Intune
  4. DMicrosoft Sentinel
Show answer & explanation

Correct answer: C. Microsoft Intune

Microsoft Intune is a cloud-based service that focuses on mobile device management (MDM) and mobile application management (MAM), allowing administrators to manage endpoints and enforce compliance policies.

Why the other options are wrong

  • A. Microsoft Information Protection (MIP) is for classifying, labeling, and protecting sensitive data, not device compliance.
  • B. Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) for monitoring and protecting cloud apps, not device management.
  • D. Microsoft Sentinel is a Security Information and Event Management (SIEM) solution for security analytics and threat intelligence.

Microsoft Intune

A cloud-based endpoint management solution that manages user access and simplifies app and device management across various platforms.

  • Enforces device compliance policies (e.g., OS version, encryption).
  • Manages mobile devices (MDM) and mobile applications (MAM).
  • Integrates with Azure AD for identity-driven access.

Memory trick: Intune ensures your devices are 'In Tune' with policies.

More Describe core Microsoft 365 services and concepts questions