Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your organization is implementing a zero-trust security model. You need to ensure that all access to corporate resources from mobile devices is conditional based on device compliance, user risk, and location. Which Microsoft Entra ID feature should you use?

⚠ Common exam trap

Candidates often confuse Microsoft Intune (which manages device compliance) with the policy engine that enforces access decisions, failing to realize that Conditional Access is the orchestration layer that consumes compliance, risk, and location signals to enforce zero-trust access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access policies

Conditional Access policies in Microsoft Entra ID are the correct choice because they allow you to enforce access controls based on conditions such as device compliance (via integration with Microsoft Intune), user risk (via integration with Identity Protection), and location (via IP ranges or named locations). This directly supports the zero-trust principle of 'never trust, always verify' by evaluating signals before granting access to corporate resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Identity Protection

    Why it's wrong here

    Identity Protection is Microsoft Entra ID's risk-detection service that analyzes sign-in attempts for anomalies such as impossible travel, leaked credentials, or unfamiliar locations, producing user and sign-in risk scores. However, it does not enforce access decisions itself—it cannot require device compliance, block by geography, or trigger MFA directly. Instead, its risk signals feed into Conditional Access, which then makes the actual authorization decision as part of a zero-trust architecture.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune is a cloud-based mobile device management (MDM) and mobile application management (MAM) solution that defines device compliance policies, such as requiring disk encryption, a minimum OS version, or jailbreak detection, and tracks device posture through enrollment. While Intune can mark a device as compliant or non-compliant, it does not independently evaluate sign-in context or enforce access at the authentication layer. Its compliance status is merely one condition that Conditional Access consumes alongside other signals—without Conditional Access, Intune's compliance state has no direct impact on granting or denying access.

  • ✓

    Conditional Access policies

    Why this is correct

    Conditional Access is Microsoft Entra ID's policy engine that evaluates real-time signals—including user/group membership, location, application, device compliance, and risk scores—to allow, deny, or require additional verification such as MFA or a compliant device. It natively integrates with Intune compliance status and Identity Protection risk assessments, making it the central enforcement point for zero-trust access control. By combining these signals into granular, context-aware policies, Conditional Access directly enforces the zero-trust principle of never trusting implicit access.

  • ✗

    Microsoft Defender XDR

    Why it's wrong here

    Microsoft Defender XDR is a threat protection suite that collects and correlates signals across endpoints, email, identities, and applications to detect, investigate, and respond to complex attacks. While it can send device risk scores to Conditional Access or trigger automated response actions, it does not directly enforce pre-authentication access decisions like blocking a sign-in based on location or requiring MFA. Its role is primarily post-breach detection and remediation, not proactive access control, so it cannot alone implement zero trust access policies.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.