Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A company uses Microsoft Entra ID. They want to block all access to corporate applications from devices that are not managed by their organization. They require that only devices enrolled in Microsoft Intune and compliant with company policies can access company resources. Which Microsoft Entra ID feature should they use?

⚠ Common exam trap

Candidates often confuse Identity Protection's user risk policies with device-based controls, or assume that simply joining a device to Entra ID (Option D) is sufficient to enforce compliance, when in fact a Conditional Access policy is required to block non-compliant devices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access policy requiring device compliance

Conditional Access policies in Microsoft Entra ID can enforce device compliance as a condition for granting access. By configuring a policy that requires devices to be marked as compliant in Microsoft Intune, only devices enrolled and meeting company policies can access corporate applications, effectively blocking unmanaged devices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conditional Access policy requiring device compliance

    Why this is correct

    Conditional Access is Microsoft Entra ID's policy engine that can evaluate device compliance status from Microsoft Intune at sign-in time. By targeting all users and cloud apps with a 'Require device to be marked as compliant' grant, the policy will block access for any device that is not enrolled and compliant with the organization's compliance policies. This directly satisfies the goal of blocking all access from non-compliant devices, and it can also be combined with session controls to continuously re-evaluate compliance.

  • ✗

    Identity Protection with user risk policy

    Why it's wrong here

    Identity Protection's user risk policy evaluates the probability that a user's identity has been compromised, using signals like leaked credentials, suspicious sign-ins, and impossible travel. While it can block sign-in for high-risk users, it makes no assessment of the device's compliance state, enrollment status, or management. A user on a non-compliant or unmanaged device with a low-risk profile would still be allowed access, so this option cannot block all access based on device compliance.

  • ✗

    Privileged Identity Management (PIM)

    Why it's wrong here

    Privileged Identity Management (PIM) is designed for just-in-time, time-bound activation of privileged roles such as Global Administrator, and it requires approval or Multi-Factor Authentication for role activation. It does not evaluate the endpoint's compliance with device policies, nor does it gate ordinary user access to applications. Even if PIM is used, non-privileged users on non-compliant devices would still be able to sign in, so it cannot serve as a device-based access control mechanism.

  • ✗

    Microsoft Entra ID Join process

    Why it's wrong here

    Microsoft Entra ID Join is the process that creates a device identity in Microsoft Entra ID and establishes a trust relationship to enable SSO and access to cloud resources. However, merely joining a device does not enforce compliance or block access; it only registers the device and provides directory-level identification. Compliance enforcement occurs only when a Conditional Access policy references the device's compliance state (which Intune calculates) as a condition—otherwise, joined devices are treated no differently than unmanaged ones.

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.