Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Hard

A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices have a specific application, 'ContosoApp.exe', installed and running. If the application is not present or not running, the device should be marked as non-compliant. Which Intune feature should the administrator use to achieve this?

  1. APowerShell script deployment
  2. BConfiguration profile (Device features)
  3. CCustom compliance settings
  4. DWin32 app deployment
Show answer & explanation

Correct answer: C. Custom compliance settings

Custom compliance settings allow administrators to define compliance rules based on custom scripts (PowerShell) that check for specific application presence or running state. If the script returns a non-compliant status, the device is marked as such.

Why the other options are wrong

  • A. PowerShell script deployment runs scripts but doesn't directly integrate with the compliance engine to mark devices as compliant/non-compliant based on script output without custom compliance settings.
  • B. Configuration profiles apply settings but are not designed to dynamically check for application running status and mark compliance based on it.
  • D. Win32 app deployment installs applications but doesn't inherently mark a device as non-compliant if the app is missing or not running.

Intune Custom Compliance Settings

Allows administrators to extend Intune's compliance capabilities by defining custom rules using PowerShell scripts, enabling checks for specific device configurations or application states.

  • Uses PowerShell scripts to evaluate compliance.
  • Enables checks beyond built-in compliance settings.
  • Reports device compliance status back to Intune.

Memory trick: Custom compliance scripts let you define your own strict rules.

More Manage identity and compliance (10-15%) questions