Continue your lesson
Trace device identity, enrollment, assignment, policy evaluation, deployment, and reporting as separate stages.
Block 1 of 3Compare App protection policy · App data-transfer restriction
Current · 12 min
Compare App protection policy · App data-transfer restriction
Optional concept notes
App protection policy
Protects organizational data inside supported applications with data and access controls.
App data-transfer restriction
Controls whether organizational data can move to unmanaged apps storage or services.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 2 of 3Compare Managed-device app configuration · Managed-app configuration · Selective app wipe
18 min
Compare Managed-device app configuration · Managed-app configuration · Selective app wipe
Optional concept notes
Managed-device app configuration
Delivers application settings through the mobile-device-management channel to an enrolled device.
Managed-app configuration
Delivers supported application settings through the Intune app-management channel and can apply without requiring device enrollment.
Selective app wipe
Removes organizational application data while leaving personal data on the device.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 3 of 3Compare Conditional launch setting · App PIN requirement · App protection Conditional Access
15 min
Compare Conditional launch setting · App PIN requirement · App protection Conditional Access
Optional concept notes
Conditional launch setting
Blocks or wipes protected application data when a device or app exceeds a risk threshold.
App PIN requirement
Requires a separate access check before protected organizational app data opens.
App protection Conditional Access
Requires an app protection policy before resource access; the former approved-client-app grant is legacy and read-only for new policy design.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Practice the reasoning here
Build a small fictional pilot. Map each user, device, group, policy, and report before deciding where a failed deployment should be repaired.
- State the expected result before changing or testing anything.
- Name the observation, command, log, or report that would confirm it.
- Explain why the closest alternative does not fit the same requirement.
Check the whole objective
This unlocks objective 4.2 for recall. The latest checkpoint needs 70% or higher; a lower result puts the lesson back near the front of your timeline.