Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium
A company uses Microsoft Intune to manage its corporate-owned iOS devices. Due to compliance requirements, all devices must enforce a minimum passcode length of 6 characters and automatically lock after 5 minutes of inactivity. Additionally, users must be prevented from installing apps from the App Store. Which Intune policy type should the Microsoft 365 Endpoint Administrator use to configure these settings?
- AConfiguration Profile > Device features
- BApp protection policy
- CConfiguration Profile > Device restrictions
- DCompliance policy
Show answer & explanationAnswer & explanation
Correct answer: C. Configuration Profile > Device restrictions
Device restrictions policies are specifically designed to control various hardware features, system functions, app installations, and security settings on mobile devices, including passcode requirements and app store access.
Why the other options are wrong
- A. Device features policies typically configure things like AirPrint, VPN, Wi-Fi, not general device restrictions like passcode length or App Store access.
- B. App protection policies focus on protecting corporate data within apps, not device-wide settings or app installation restrictions.
- D. Compliance policies define the conditions a device must meet to be considered compliant, they do not enforce the settings themselves.
Intune iOS Device Restrictions
An Intune configuration profile type used to control various hardware, system, and app-related settings on iOS/iPadOS devices, including security features like passcodes and app source restrictions.
- Configured via Configuration Profiles in Intune.
- Enforces security settings like passcode length and auto-lock.
- Can restrict App Store access, camera, AirDrop, etc.
Memory trick: Restrictions secure the device's core functions.