Continue your lesson
Trace device identity, enrollment, assignment, policy evaluation, deployment, and reporting as separate stages.
Block 1 of 4Compare Device compliance policy · Action for noncompliance
Current · 12 min
Compare Device compliance policy · Action for noncompliance
Optional concept notes
Device compliance policy
Evaluates endpoint state against requirements such as encryption password and threat level.
Action for noncompliance
Schedules notifications retirement or other responses after a device fails compliance checks.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 2 of 4Compare Device-based Conditional Access · Compliance grace period
15 min
Compare Device-based Conditional Access · Compliance grace period
Optional concept notes
Device-based Conditional Access
Uses compliant or joined device state when deciding whether to grant resource access.
Compliance grace period
Allows a defined interval before a newly noncompliant device is marked noncompliant.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 3 of 4Compare Intune scope tag · Intune role-based access control
18 min
Compare Intune scope tag · Intune role-based access control
Optional concept notes
Intune scope tag
Limits which managed objects an administrator can see and administer.
Intune role-based access control
Grants task-specific Intune permissions through roles assignments and scope groups.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 4 of 4Compare Device category · Intune assignment filter
12 min
Compare Device category · Intune assignment filter
Optional concept notes
Device category
Lets a device be labeled for grouping reporting or targeted administrative workflows.
Intune assignment filter
Includes or excludes devices at assignment time by evaluating device properties.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Practice the reasoning here
Build a small fictional pilot. Map each user, device, group, policy, and report before deciding where a failed deployment should be repaired.
- State the expected result before changing or testing anything.
- Name the observation, command, log, or report that would confirm it.
- Explain why the closest alternative does not fit the same requirement.
Check the whole objective
This unlocks objective 1.3 for recall. The latest checkpoint needs 70% or higher; a lower result puts the lesson back near the front of your timeline.