Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Medium
A company uses Microsoft Intune to manage its devices. A new compliance policy states that all Windows 11 devices must have BitLocker enabled and a specific Windows Defender Antivirus configuration. You create a new device compliance policy in Intune for Windows 11. To ensure this policy is enforced, what is the next crucial step after creating the policy?
- AAssign the compliance policy to a group of users or devices.
- BConfigure a Conditional Access policy to block non-compliant devices.
- CCreate an App protection policy for Windows devices.
- DManually restart all Windows 11 devices to apply the policy.
Show answer & explanationAnswer & explanation
Correct answer: A. Assign the compliance policy to a group of users or devices.
After creating any policy in Intune, it must be assigned to a group of users or devices for it to take effect. Without assignment, the policy exists but is not applied to any endpoints.
Why the other options are wrong
- B. While a Conditional Access policy is crucial for *enforcing* compliance (e.g., blocking access), it only works *after* the device compliance policy has been assigned and evaluated. Assignment is the prerequisite.
- C. App protection policies are for data within apps, not device-level compliance like BitLocker or Antivirus.
- D. Policies are typically applied during device check-ins or user sign-ins; a manual restart is not required for policy application.
Intune Policy Assignment
The process of linking a created policy (e.g., compliance, configuration, app protection) to specific user groups or device groups within Microsoft Intune, enabling the policy to be evaluated and enforced on those targets.
- Policies are inactive until assigned.
- Can be assigned to user groups or device groups.
- Assignment determines the scope of policy application.
Memory trick: Create, Assign, Monitor: The Intune policy's journey, in order.