Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium
A Microsoft 365 Endpoint Administrator is managing a fleet of corporate-owned Android Enterprise fully managed devices. A new security policy dictates that all devices must have a minimum screen lock password length of 6 characters and automatically lock after 5 minutes of inactivity. Which Intune policy type should be used to enforce these settings?
- AUpdate policy
- BDevice restriction policy
- CApp configuration policy
- DDevice compliance policy
Show answer & explanationAnswer & explanation
Correct answer: B. Device restriction policy
Device restriction policies are designed to control various device settings, including password requirements and screen lock behavior, for different operating systems. This makes it the appropriate policy type for enforcing the specified security requirements on Android Enterprise fully managed devices.
Why the other options are wrong
- A. Update policies manage OS and app updates, not screen lock or password settings.
- C. App configuration policies are used to configure settings within specific applications, not device-level security features.
- D. Device compliance policies define conditions that devices must meet to be considered compliant, but the actual enforcement of settings like password length is done via device restriction policies.
Android Enterprise Device Restrictions
Intune policies used to configure and enforce various device-level settings, including security features like password requirements and screen lock behavior, on Android Enterprise devices.
- Part of device configuration profiles
- Supports various Android Enterprise management modes
- Used to enforce security, hardware, and app settings
Memory trick: Every Device Needs a Rule, From Apps to Security Tool.