QuestionQ154

Plan and implement identity and security

You have the following:

  • A Microsoft 365 E5 tenant
  • An on-premises Active Directory domain
  • A hybrid Azure Active Directory (Azure AD) tenant
  • An Azure Active Directory Domain Services (Azure AD DS) managed domain
  • An Azure Virtual Desktop deployment

The Azure Virtual Desktop deployment includes personal desktops that are hybrid joined to the on-premises domain and enrolled in Microsoft Intune.

You need to configure the security settings for the Microsoft Edge browsers on the personal desktops.

Proposed solution: Configure a compliance policy in Intune.

Does this solution meet the goal of configuring the security settings for the Microsoft Edge browsers on the personal desktops?

  • A Yes
  • B No
Explanation

Intune compliance policies are used to evaluate and report on whether a device meets defined security or configuration criteria (for example, to drive Conditional Access decisions) — they do not push or enforce actual setting values to a device. To configure and enforce Microsoft Edge browser security settings, you need to create a device configuration profile (such as a Settings Catalog or Administrative Templates profile, or apply the Microsoft Edge security baseline) in Intune. Since a compliance policy cannot deliver or enforce Edge settings, this solution does not meet the goal.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!