You assign a compliance policy named Policy1 to Group1, and Policy1 marks devices Compliant only when their security settings match the policy. Devices not in Group1 are appearing as Compliant. To ensure only devices assigned a compliance policy can be shown as Compliant and all others appear Not compliant, what should you configure in the Intune admin center?
Choose an answer
Tap an option to check your answer.
Correct answer: From Device compliance, configure the Compliance policy settings..
Why this is the answer
The correct answer is to configure Compliance policy settings from Device compliance. This is where you can set the global default for devices not assigned a compliance policy. By changing the "Mark devices with no compliance policy assigned as" setting to "Not compliant," you ensure that only devices explicitly evaluated by a compliance policy can achieve a Compliant status. Configuring Conditional access settings from Endpoint security controls access to resources based on device compliance, but it doesn't define the compliance status itself. Modifying Diagnostic settings from Tenant administration relates to logging and monitoring, not compliance evaluation. Modifying actions for noncompliance in Policy1 defines what happens when devices fail Policy1, but it doesn't address devices not assigned any policy.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed