Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Easy
A Microsoft 365 Endpoint Administrator is configuring Microsoft Intune to manage corporate-owned Android Enterprise devices. The goal is to restrict users from installing apps from unknown sources and prevent the use of developer options. Which type of Intune policy should be used to achieve this?
- AApp configuration policy
- BCompliance policy
- CDevice configuration profile
- DApp protection policy
Show answer & explanationAnswer & explanation
Correct answer: C. Device configuration profile
Device configuration profiles are used to manage device-level settings, including security features like restricting unknown sources and disabling developer options, across various platforms like Android Enterprise.
Why the other options are wrong
- A. App configuration policies manage settings within specific applications, not device-wide restrictions.
- B. Compliance policies define conditions devices must meet to be considered compliant, but don't directly configure settings.
- D. App protection policies (MAM) protect data within apps, independent of device enrollment, and don't manage system-level features.
Intune Device Configuration Profile
A Microsoft Intune device configuration profile is a set of settings that can be deployed to devices to manage their features, security, and behavior.
- Manages device-level settings.
- Applicable across various OS platforms (Windows, iOS, Android, macOS).
- Used for restrictions, Wi-Fi, VPN, email profiles, etc.
Memory trick: Configuration profiles set the device's main 'config'.