Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A company must prevent non-compliant devices from accessing Exchange Online and SharePoint Online. Which design should you recommend?

⚠ Common exam trap

Test-takers frequently confuse network-level controls (like Azure Firewall) with identity-driven access controls (like Conditional Access), assuming a firewall can filter SaaS traffic, but Azure Firewall cannot inspect or enforce device compliance for Microsoft 365 services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access policy requiring a compliant device.

Conditional Access policies in Microsoft Entra ID (formerly Azure AD) can enforce device compliance by integrating with Microsoft Intune. When a policy requires a compliant device, it checks the device's compliance status before granting access to Exchange Online and SharePoint Online, blocking non-compliant devices at the authentication layer. This is the correct design because it directly controls access to these cloud services based on device health.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conditional Access policy requiring a compliant device.

    Why this is correct

    A Conditional Access policy that requires a compliant device works by evaluating the device's compliance state (reported by Intune or a mobile device management solution) as a grant control at the moment of Entra ID authentication. When a user attempts to reach Microsoft 365 apps such as Exchange Online or SharePoint Online, the policy checks that the device meets all compliance policies—like encryption, OS patch level, and jailbreak status—before issuing an access token. This is the correct approach because device compliance is an identity-driven signal that integrates directly with the Entra ID authentication and authorization pipeline, and it can be scoped to require this for all cloud app access.

  • ✗

    Azure Firewall application rule.

    Why it's wrong here

    Azure Firewall application rules are a network-layer element that filter outbound HTTP/S traffic based on fully qualified domain names (FQDNs) for resources within an Azure virtual network. They are completely unaware of the user's identity, the OAuth tokens, or the device compliance status that Entra ID evaluates for Microsoft 365 access. Moreover, Microsoft's guidance explicitly says to bypass Azure Firewall for trusted Microsoft 365 endpoints because the firewall cannot decrypt or inspect modern TLS/HTTPS traffic for identity conditions, so it can never enforce device compliance for Exchange or SharePoint.

  • ✗

    Storage account network rule.

    Why it's wrong here

    Storage account network rules (such as IP ACLs, virtual-network service endpoints, or private endpoints) control access only to the Azure Blob, File, Queue, or Table storage endpoints, not to Microsoft 365 services like Exchange Online and SharePoint Online. These rules are not evaluated during an Entra ID OAuth authentication flow; they only operate on the data-plane call to the storage endpoint. Therefore, even if a non-compliant device attempts to access a shared file in SharePoint Online, a storage firewall has no mechanism to see or block that request, and it could not enforce a device compliance check.

  • ✗

    Resource lock on the Microsoft 365 tenant.

    Why it's wrong here

    An Azure resource lock (CanNotDelete or ReadOnly) is designed to prevent accidental deletion or modification of an Azure subscription, resource group, or resource by administrative operations. It does not extend to user sign-in conditions or application-access decisions; Microsoft 365 as a SaaS offering is not a deployable Azure resource, and resource locks have no bearing on entitlement or device posture during authentication. Even if a lock were placed on an Azure resource representing the tenant, it would not evaluate whether a user's device is compliant before allowing access to Exchange Online or SharePoint Online.

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.