Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium

A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned iOS devices enforce a passcode policy that requires a minimum length of 6 characters and auto-locks after 5 minutes of inactivity. Users should also be prevented from using simple passcodes. Which Intune policy type should be used?

  1. ADevice configuration profile (Device restrictions)
  2. BDevice compliance policy
  3. CiOS/iPadOS update policy
  4. DApp protection policy
Show answer & explanation

Correct answer: A. Device configuration profile (Device restrictions)

Device configuration profiles, specifically the 'Device restrictions' template for iOS/iPadOS, are used to configure device-level settings such as passcode requirements (length, complexity) and auto-lock settings. This directly enforces the desired security posture on the devices.

Why the other options are wrong

  • B. Compliance policies define conditions devices must meet (e.g., passcode enabled) but don't configure the actual passcode settings.
  • C. iOS/iPadOS update policies manage OS updates, not device security settings like passcodes.
  • D. App protection policies protect data within apps, not device-level security settings like passcodes.

Intune iOS Device Restrictions

Intune Device configuration profiles, using the 'Device restrictions' template for iOS/iPadOS, allow administrators to enforce various device-level security and functional settings, including passcode policies, hardware feature restrictions, and app usage.

  • Manages core device security and functionality.
  • Covers passcode requirements, camera usage, app store access, etc.
  • Applied to corporate-owned devices to maintain control.

Memory trick: Device Restrictions: Lock down the 'Device' itself.

More Manage devices and apps (55-60%) questions