Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Easy
A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned iOS devices have a standardized set of security and functional configurations, such as passcode requirements, device feature restrictions (e.g., camera use), and Wi-Fi profiles. Which Intune profile type is primarily used for these general device settings?
- ADevice compliance policies
- BVPN profiles
- CDevice configuration profiles
- DApp configuration policies
Show answer & explanationAnswer & explanation
Correct answer: C. Device configuration profiles
Device configuration profiles (specifically 'Device restrictions' or 'Wi-Fi' profiles within this category) are the primary tool in Intune for deploying general security and functional settings like passcodes, feature restrictions, and Wi-Fi configurations to devices.
Why the other options are wrong
- A. Device compliance policies define conditions that devices must meet to be considered compliant, but they don't *configure* the settings themselves.
- B. VPN profiles configure VPN connections, which is a specific type of network setting, not general device configurations.
- D. App configuration policies apply settings to specific applications, not general device features.
Intune Device Configuration Profiles
A broad category of Intune policies used to deploy various settings, restrictions, and features to managed devices across different platforms.
- Includes settings for passcode, device features, network (Wi-Fi, VPN), and more.
- Platform-specific options (e.g., iOS/iPadOS, Windows).
- Used to enforce security and standardize user experience.
Memory trick: Configuration for the 'how', Compliance for the 'if'.