MD-102 · Prepare infrastructure for device management

Implement identity and compliance for devices

Objective 1.3 · Implement identity and compliance for devices.

4 learning blocksNext: about 12 minutes8 key conceptsPreview · not independently reviewed
ProgressNot started0/4 blocks learned and checked
Learn

Continue your lesson

Trace device identity, enrollment, assignment, policy evaluation, deployment, and reporting as separate stages.

0/4blocks complete
Block 1 of 4

Compare Device compliance policy · Action for noncompliance

Current · 12 min
Learn with your providerOpen a provider lesson below, then return to try four related questions.
Optional concept notes

Device compliance policy

Evaluates endpoint state against requirements such as encryption password and threat level.

Action for noncompliance

Schedules notifications retirement or other responses after a device fails compliance checks.

Your sessionabout 12 minutes

Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.

Block 2 of 4

Compare Device-based Conditional Access · Compliance grace period

15 min
Optional concept notes

Device-based Conditional Access

Uses compliant or joined device state when deciding whether to grant resource access.

Compliance grace period

Allows a defined interval before a newly noncompliant device is marked noncompliant.

Your sessionabout 15 minutes

Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.

Block 3 of 4

Compare Intune scope tag · Intune role-based access control

18 min
Optional concept notes

Intune scope tag

Limits which managed objects an administrator can see and administer.

Intune role-based access control

Grants task-specific Intune permissions through roles assignments and scope groups.

Your sessionabout 18 minutes

Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.

Block 4 of 4

Compare Device category · Intune assignment filter

12 min
Optional concept notes

Device category

Lets a device be labeled for grouping reporting or targeted administrative workflows.

Intune assignment filter

Includes or excludes devices at assignment time by evaluating device properties.

Your sessionabout 12 minutes

Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.

No setup required

Practice the reasoning here

Build a small fictional pilot. Map each user, device, group, policy, and report before deciding where a failed deployment should be repaired.

  1. State the expected result before changing or testing anything.
  2. Name the observation, command, log, or report that would confirm it.
  3. Explain why the closest alternative does not fit the same requirement.
Your next milestone

Check the whole objective

This unlocks objective 1.3 for recall. The latest checkpoint needs 70% or higher; a lower result puts the lesson back near the front of your timeline.

One lesson at a time.Your block checks prepare you for this milestone. A score of 70% or higher advances the course; finishing a practice session completes your daily goal.
Official blueprint references
Official Endpoint Administrator certification overviewMicrosoft ↗Official MD-102 study guideMicrosoft ↗