Microsoft MD-102: Device Configuration Profiles and Policies — Study Guide

Part of the Microsoft Endpoint Administrator Associate MD-102 — Study Guide. Practice with verified answers in the Microsoft exam hub, or take timed practice tests on ExamRoll.io.

Overview

Device configuration and policy management in Microsoft Intune establishes consistent, secure operating states across Windows, macOS, iOS/iPadOS, and Android. Admins combine configuration profiles, endpoint security policies, compliance policies, Delivery Optimization, and Windows Update for Business so that devices are provisioned with required settings, enforced for security posture, continuously updated, and allowed access to resources based on compliance state. Effective design hinges on understanding settings sources (Settings Catalog, Administrative Templates, device restrictions, and custom OMA-URI), security policy scope and precedence, assignment mechanics (include/exclude and filters), and the integration between compliance and Conditional Access.

Configuration Profiles and Settings Sources

Configuration profiles deliver operating system and application settings. For Windows, core profile types include device restrictions, endpoint protection (legacy template), administrative templates (ADMX-backed), and Settings Catalog. When a required setting is unavailable in templates, a custom OMA-URI profile targets the underlying MDM CSP.

Device restrictions are curated templates that centralize common controls such as password and sign-in requirements, browser and Store controls, privacy, Bluetooth and peripheral access, and kiosk/Single App Mode. On Android Enterprise (work profile and fully managed), kiosk configuration is in the Device experience category. On iOS/iPadOS, restrictions include app install controls, AirDrop, screen capture, and iCloud settings. On Windows, device restrictions cover BitLocker prerequisites, account controls, and UX lockdowns.

The endpoint protection device profile template predates Endpoint security and configures Windows Defender Antivirus, Firewall, BitLocker, SmartScreen, and Exploit Guard settings. For new deployments, favor Endpoint security profiles for these domains to streamline posture reporting and reduce cross-template conflicts; keep endpoint protection device profiles only where a needed knob is absent elsewhere.

Administrative Templates map to ADMX-backed policies via the ADMX-backed MDM CSP. They mirror familiar Group Policy paths for Windows and Microsoft 365 Apps. Use them when you want the GPO-like model (e.g., Office policy settings) and for consistency in migrations from on-premises GPOs.

Settings Catalog is the most flexible, forward-looking source that enumerates nearly all CSP and ADMX-backed settings with search, categories, and scope to device/user. Prefer Settings Catalog when you need precise selection, cross-template settings in one profile, or to replace monolithic templates.

Custom OMA-URI profiles configure any CSP directly when a setting isn’t exposed in Intune UI. Define the exact OMA-URI path (for example, ./Vendor/MSFT/Policy/Config/Defender/ScanAvgCPULoadFactor), data type, and value. Use this also to ingest third-party ADMX for ADMX-backed CSP scenarios, or to push macOS/iOS payloads (e.g., plist keys) that aren’t in native templates.

To minimize conflicts, configure a given setting in only one policy source. Intune will flag a per-setting Conflict if multiple assigned policies set the same key; device behavior may be undefined or last-write, so consolidation is best practice.

Endpoint Security Profiles and Threat Surface

The Endpoint security node delivers purpose-built policies with security-centric reporting. Use these in priority order over general configuration profiles for security settings:

For Microsoft Defender for Endpoint onboarding, create an Endpoint detection and response (EDR) policy in Intune to deploy the onboarding package and enable sensor data collection. On macOS, apply Defender AV settings through a configuration profile using the Defender preference domain to minimize administrative effort.

Security baselines are curated collections of recommended security settings. Use them to quickly reach a defensible baseline, then layer Endpoint security profiles for exceptions and advanced controls.

Compliance, Conditional Access, and Assignment Mechanics

Compliance policies evaluate device posture against organizational requirements and produce a binary compliant/noncompliant state (with an “in grace period” indicator). Common Windows rules include OS version/build thresholds, password complexity, BitLocker required, Microsoft Defender status, TPM presence, and Microsoft Defender for Endpoint device risk level. For mobile, require PIN, encryption, block jailbroken/rooted, and OS version minimums.

Actions for noncompliance define enforcement timing and escalation. The default action marks the device noncompliant; you can schedule additional actions such as sending email notifications to users and admins and remotely locking the device on supported platforms. Each action supports a grace period (in days). While a device is in grace, it remains compliant for Conditional Access evaluation, enabling user remediation without immediate access loss.

Conditional Access uses compliance state to gate access. A common pattern is “Require device to be marked as compliant” for cloud apps, which relies on Intune to assert compliance. Combine with additional conditions such as client app types to control legacy authentication. Pairing device compliance with CA ensures only trusted and managed devices access corporate resources.

Assignments determine scope. Include groups (user/device) to target; use group exclusions to remove subsets. Exclusions win over inclusions. Filters refine assignments at evaluation time based on device properties (OS version, manufacturer, enrollment type, ownership, join type, etc.) with include or exclude logic, especially useful when assigning to “All devices/users” while targeting only eligible endpoints. To avoid policy conflicts, align ownership and platform scoping, avoid setting the same CSP keys across multiple policy types, and prefer a single source (e.g., Endpoint security) for security controls. For Windows Update policies, remember precedence: a Feature updates policy that pins a specific release overrides Update ring feature deferral; Expedited quality updates override deferrals and deadlines for the selected update.

Windows Update for Business and Delivery Optimization

Windows Update for Business (WUfB) keeps devices current without WSUS or SCCM. Use three complementary policy types:

Delivery Optimization (DO) reduces WAN utilization by peer-sharing content such as Windows updates, Microsoft 365 Apps, Intune Win32 apps, and Microsoft Store apps. Configure DO with a Settings Catalog or Delivery Optimization profile. Key controls include download mode, bandwidth limits, cache behavior, and VPN awareness. Typical modes are:

Set bandwidth as a percentage of measured throughput or as absolute limits, distinguish foreground vs background, cap upload bandwidth, define cache size and file age, and block peering on VPN. Combine DO with WUfB rings to minimize risk and bandwidth impact while maintaining update velocity.

Practical Problem Scenario

Contoso Ltd. operates 2,500 Windows 11 laptops across global offices and 300 macOS devices used by engineering. They must: enforce disk encryption, standardize Defender protections, control Windows update rollout with emergency patch ability, reduce WAN usage, and block access to Microsoft 365 unless devices are compliant. Some Windows devices are used by contractors and shouldn’t receive kiosk or corporate UX restrictions.

  1. Create Endpoint security Disk encryption policies
  1. Create Endpoint security Antivirus and Attack surface reduction policies
  1. Onboard to Microsoft Defender for Endpoint
  1. Define compliance policies with grace periods and actions
  1. Configure Conditional Access
  1. Implement Windows Update for Business
  1. Optimize content with Delivery Optimization
  1. Assign with groups and filters; avoid conflicts

This approach uses Intune Endpoint security for hardened posture, compliance plus Conditional Access for access control, WUfB for controlled updates with emergency response, and Delivery Optimization for bandwidth efficiency—mapped to Contoso’s mixed ownership and multi-platform environment for reliable, scalable endpoint management.


Device Enrollment and Azure AD Join · All domains · Application Management and Deployment

Practice these questions → · Timed practice on ExamRoll.io →

Pass the whole exam — not just this question

You found this answer. Get every verified question and explanation in one place, and save hours of prep. Free to start.

Pass your exam →

Browse Microsoft →

Related guides

All-in-one access

One subscription. Every exam.

Every plan unlocks unlimited answer search, practice tests, AI explanations, and the full resource library — in 20+ languages.

Monthly
24.87
Just €0.83/day
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

Best value
12 months
179.87
Just €0.49/daySave 40%
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

✓ Free plan included · ✓ Cancel anytime · ✓ All plans unlock the full product