- Answers: A, B, C, D
To restrict access, you'll need to make sure you have devices joined to Azure AD and enrolled in Intune. Then, you need to determine their compliance devices by configuring a device compliance policy in Intune. After that, you have to restrict access for those devices based on their compliance status by creating a conditional access policy in Azure AD.
More information:
https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/configure-conditional-access.
- Answer: B
The machine's details list the operating system as Windows 10 and its domain as contoso.com, which qualifies it for membership in group 2. Since it has no tags, it will not be in group 1. Since a machine will only be added to the highest-ranking group, group 2 overrules its group 3 eligibility.
More information: https://docs.microsoft.com...