- Answers: A and B
Compliance policies can be used to identify devices using operating systems that are too old or new to be compliant. Without a conditional access policy, your options are limited when it comes to responding to noncompliance. Add a conditional access policy to restrict specific access rather than locking a device or just sending an email.
More information: https://docs.microsoft.com/en-us/intune/device-compliance-get-started.
- Answer: C
Apple devices require a valid MDM push certificate to be configured. If Apple devices are the only devices encountering enrollment issues, that's a good place to start your investigation.
More information: https://docs.microsoft.com/en-us/intune/apple-mdm-push-certificate-get.