AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company uses Microsoft Entra ID. They want to block all access to corporate applications from devices that are not managed by their organization. They require that only devices enrolled in Microsoft Intune and compliant with company policies can access company resources. Which Microsoft Entra ID feature should they use?
⚠ Common exam trap
Candidates often confuse Identity Protection's user risk policies with device-based controls, or assume that simply joining a device to Entra ID (Option D) is sufficient to enforce compliance, when in fact a Conditional Access policy is required to block non-compliant devices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policy requiring device compliance
Conditional Access policies in Microsoft Entra ID can enforce device compliance as a condition for granting access. By configuring a policy that requires devices to be marked as compliant in Microsoft Intune, only devices enrolled and meeting company policies can access corporate applications, effectively blocking unmanaged devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access policy requiring device compliance
Why this is correct
Conditional Access is Microsoft Entra ID's policy engine that can evaluate device compliance status from Microsoft Intune at sign-in time. By targeting all users and cloud apps with a 'Require device to be marked as compliant' grant, the policy will block access for any device that is not enrolled and compliant with the organization's compliance policies. This directly satisfies the goal of blocking all access from non-compliant devices, and it can also be combined with session controls to continuously re-evaluate compliance.
- ✗
Identity Protection with user risk policy
Why it's wrong here
Identity Protection's user risk policy evaluates the probability that a user's identity has been compromised, using signals like leaked credentials, suspicious sign-ins, and impossible travel. While it can block sign-in for high-risk users, it makes no assessment of the device's compliance state, enrollment status, or management. A user on a non-compliant or unmanaged device with a low-risk profile would still be allowed access, so this option cannot block all access based on device compliance.
- ✗
Privileged Identity Management (PIM)
Why it's wrong here
Privileged Identity Management (PIM) is designed for just-in-time, time-bound activation of privileged roles such as Global Administrator, and it requires approval or Multi-Factor Authentication for role activation. It does not evaluate the endpoint's compliance with device policies, nor does it gate ordinary user access to applications. Even if PIM is used, non-privileged users on non-compliant devices would still be able to sign in, so it cannot serve as a device-based access control mechanism.
- ✗
Microsoft Entra ID Join process
Why it's wrong here
Microsoft Entra ID Join is the process that creates a device identity in Microsoft Entra ID and establishes a trust relationship to enable SSO and access to cloud resources. However, merely joining a device does not enforce compliance or block access; it only registers the device and provides directory-level identification. Compliance enforcement occurs only when a Conditional Access policy references the device's compliance state (which Intune calculates) as a condition—otherwise, joined devices are treated no differently than unmanaged ones.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.