Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Easy

A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned iOS devices have a standardized set of security and functional configurations, such as passcode requirements, device feature restrictions (e.g., camera use), and Wi-Fi profiles. Which Intune profile type is primarily used for these general device settings?

  1. ADevice compliance policies
  2. BVPN profiles
  3. CDevice configuration profiles
  4. DApp configuration policies
Show answer & explanation

Correct answer: C. Device configuration profiles

Device configuration profiles (specifically 'Device restrictions' or 'Wi-Fi' profiles within this category) are the primary tool in Intune for deploying general security and functional settings like passcodes, feature restrictions, and Wi-Fi configurations to devices.

Why the other options are wrong

  • A. Device compliance policies define conditions that devices must meet to be considered compliant, but they don't *configure* the settings themselves.
  • B. VPN profiles configure VPN connections, which is a specific type of network setting, not general device configurations.
  • D. App configuration policies apply settings to specific applications, not general device features.

Intune Device Configuration Profiles

A broad category of Intune policies used to deploy various settings, restrictions, and features to managed devices across different platforms.

  • Includes settings for passcode, device features, network (Wi-Fi, VPN), and more.
  • Platform-specific options (e.g., iOS/iPadOS, Windows).
  • Used to enforce security and standardize user experience.

Memory trick: Configuration for the 'how', Compliance for the 'if'.

More Manage devices and apps (55-60%) questions