Microsoft 365 FundamentalsDescribe core Microsoft 365 services and conceptsHard

A Microsoft 365 administrator is responsible for ensuring that all corporate mobile devices accessing Microsoft 365 data are compliant with company security policies, such as requiring a PIN, encrypting data, and preventing data from being copied to unauthorized apps. Which Microsoft 365 service is primarily used for this mobile device and application management?

  1. AAzure Active Directory
  2. BMicrosoft Intune
  3. CMicrosoft Purview
  4. DMicrosoft Defender for Endpoint
Show answer & explanation

Correct answer: B. Microsoft Intune

Microsoft Intune is the cloud-based service in Microsoft 365 that focuses on mobile device management (MDM) and mobile application management (MAM). It allows administrators to enforce device compliance policies, deploy applications, and protect corporate data on mobile devices.

Why the other options are wrong

  • A. Azure Active Directory manages identities and access, but not the security posture or compliance of mobile devices themselves.
  • C. Microsoft Purview focuses on data governance, compliance, and risk management across data, not primarily on mobile device and app control.
  • D. Microsoft Defender for Endpoint is an endpoint security platform for threat detection and response on devices, but Intune handles the broader device compliance and app management policies.

Microsoft Intune

A cloud-based service that focuses on mobile device management (MDM) and mobile application management (MAM) to protect organizational data.

  • Manages mobile devices (smartphones, tablets) and applications
  • Enforces compliance policies (e.g., PIN, encryption, OS version)
  • Protects corporate data within apps and prevents data leakage

Memory trick: Intune tunes your devices to be secure and compliant.

More Describe core Microsoft 365 services and concepts questions