Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Easy
A company policy dictates that all corporate-owned Windows 11 devices must have BitLocker encryption enabled and require a PIN at startup. You need to configure Microsoft Intune to enforce this policy. Which type of policy should you use?
- ADevice compliance policy
- BApp protection policy
- CConfiguration profile
- DConditional Access policy
Show answer & explanationAnswer & explanation
Correct answer: A. Device compliance policy
Device compliance policies are used to define the security and health requirements that devices must meet to be considered compliant. BitLocker encryption and PIN requirements are common compliance settings.
Why the other options are wrong
- B. App protection policies manage data within applications, not device-level security settings.
- C. Configuration profiles apply settings to devices but are not primarily used to mark devices as compliant or non-compliant for conditional access.
- D. Conditional Access policies grant or block access based on conditions, often relying on device compliance status.
Device Compliance Policy
A set of rules that devices must meet to be considered 'compliant' within Microsoft Intune, often used as a condition for Conditional Access.
- Defines security and health requirements for devices.
- Used to report compliance status to Intune.
- Can trigger Conditional Access restrictions for non-compliant devices.
Memory trick: Compliance checks if devices are aligned with company standards.