Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your company uses Microsoft Entra ID for identity management. You need to ensure that only devices compliant with your company's security policies can access corporate resources. Which solution should you implement?

⚠ Common exam trap

Candidates often confuse Microsoft Defender XDR (which handles threat detection) with device compliance enforcement, not realizing that Conditional Access with Intune is the specific mechanism to gate access based on device health.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access with device compliance policies from Microsoft Intune

Conditional Access in Microsoft Entra ID allows you to enforce access controls based on conditions, including device compliance. By integrating with Microsoft Intune, you can define device compliance policies (e.g., requiring encryption, a minimum OS version, or anti-malware status) and then configure a Conditional Access policy to block or grant access only to devices that are marked as compliant. This directly ensures that only compliant devices can access corporate resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conditional Access with device compliance policies from Microsoft Intune

    Why this is correct

    Conditional Access with device compliance policies from Microsoft Intune is the correct answer because Condition Access is the policy engine in Microsoft Entra ID that evaluates signals—including whether a device is compliant—before granting access. Intune compliance policies enforce technical requirements like OS version, disk encryption, and jailbreak detection, and report compliance status to Entra ID. The Conditional Access grant control 'Require device to be marked as compliant' then blocks non-compliant devices from accessing corporate resources. This is the standard Microsoft mechanism for enforcing device compliance at authentication time.

  • ✗

    Microsoft Purview Information Protection

    Why it's wrong here

    Microsoft Purview Information Protection is incorrect for device compliance because its purpose is data classification, sensitivity labels, and encryption applied to documents and emails. It does not inspect or enforce device health, OS patch level, or any device attribute; compliance policies are handled by Intune and enforced via Conditional Access. While it protects the content that a device might access, it makes no real-time access decision based on the device's compliance state.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is incorrect for device compliance because it is a cloud-native SIEM (Security Information and Event Management) used for log aggregation, threat detection, alerting, and incident response. Sentinel does not act as a policy enforcement point for authentication; it consumes security telemetry after the fact and cannot block a logon as an inline access control. Although you can ingest device compliance logs into Sentinel for analysis, it is not the system that enforces compliance-based access restrictions.

  • ✗

    Microsoft Defender XDR

    Why it's wrong here

    Microsoft Defender XDR is incorrect for device compliance because it is an integrated detection and response platform (across endpoint, email, identity, and cloud apps) focused on post-compromise threat hunting and automated remediation. It does not serve as a pre-access authorization engine; Conditional Access and Intune are the relevant services for ensuring only compliant devices gain access. While Defender for Endpoint can provide threat signals that influence Intune compliance (e.g., active threats), the compliance policy evaluation and access enforcement remain in Intune and Conditional Access, not in Defender XDR itself.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.