Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your organization has 500 users in Microsoft Entra ID. You need to ensure that users can only access Microsoft 365 apps from compliant devices (compliant with Intune policies). Users are already enrolled in Intune. The compliance policies are defined. You need to configure the access control mechanism. What should you do?

⚠ Common exam trap

A common mix-up: candidates confuse Intune compliance policies (which define rules) with the access control enforcement mechanism (Conditional Access), leading them to choose Option B, which incorrectly assumes compliance policies can directly revoke access without a Conditional Access policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Conditional Access policy that requires device to be marked as compliant.

Conditional Access in Microsoft Entra ID is the mechanism that enforces access controls based on signals like device compliance. By creating a policy that requires the device to be marked as compliant, you ensure that only devices meeting Intune compliance policies can access Microsoft 365 apps. This directly addresses the requirement without blocking all access or relying on automatic revocation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a Conditional Access policy that blocks all access and then create exclusions for compliant devices.

    Why it's wrong here

    This approach inverts the access model by denying everyone and relying on exclusions to allow compliant devices. Exclusions in Conditional Access are broad—any user or device that does not match the exclusion criteria bypasses the policy entirely, creating a security gap and risking lockout if a compliant device is not recognized. It also does not provide a positive grant control; 'Require device to be compliant' is a distinct grant that evaluates compliance at sign-in, not a block/exception construct.

  • ✗

    Configure Intune compliance policies to automatically revoke access for non-compliant devices.

    Why it's wrong here

    Intune compliance policies are posture-assessment tools: they define settings such as OS version, disk encryption, or jailbreak status and mark a device as compliant or non-compliant. They do not, by themselves, enforce authorization decisions; without a Conditional Access policy, a non-compliant device can still receive a token and access Microsoft 365. The revocation effect only happens when Conditional Access aggregates that compliance state as a condition, so relying solely on compliance policies leaves enforcement absent.

  • ✓

    Create a Conditional Access policy that requires device to be marked as compliant.

    Why this is correct

    This is the intended pattern because Conditional Access acts as the enforcement engine: setting the grant control 'Require device to be marked as compliant' forces Entra ID to check the device's compliance claim issued by Intune before issuing a token. If the device is non-compliant or unenrolled, access is denied, and the user may be redirected to remediation. This precisely matches the requirement that only compliant devices can access Microsoft 365 applications.

  • ✗

    Create a Conditional Access policy that requires MFA based on location.

    Why it's wrong here

    A location-based MFA policy triggers an MFA challenge based on named location conditions (e.g., untrusted IP ranges) but says nothing about whether the endpoint is managed or meets compliance requirements. After satisfying MFA, a user could still operate from a non-compliant or unknown device, so the core requirement is unfulfilled. Device compliance must be evaluated independently, typically via the 'Require device to be marked as compliant' grant control.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.