Courseiva

AZ-500 Manage identity and access Practice Question

A Conditional Access policy requiring compliant devices does not apply to Azure PowerShell access. Sign-in logs show the cloud app is excluded. What should be changed?

⚠ Common exam trap

It's easy for candidates to assume a Conditional Access policy applies to all cloud apps by default, but in reality, policies only apply to apps explicitly included, and exclusions take precedence over inclusions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Include the relevant cloud app or target all cloud apps after testing exclusions

Conditional Access policies apply only to cloud apps explicitly included in the policy. Since Azure PowerShell is excluded, the policy does not enforce the 'Require device to be marked as compliant' condition for that app. To fix this, you must either include the specific cloud app (Microsoft Azure PowerShell) or set the policy to target 'All cloud apps' and then test exclusions to ensure the compliant device requirement is applied to Azure PowerShell access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable device compliance in Intune

    Why it's wrong here

    Disabling device compliance in Intune would destroy the policy's core condition: the policy checks the `compliant` attribute that Intune reports to Microsoft Entra ID. Without Intune compliance policies and evaluation, devices default to non-compliant or unknown, so the CA policy would either block everything or fail to evaluate, not accomplish anything. You would also lose the ability to require enrollment and health attestation, so this is not a valid action.

  • ✗

    Convert the policy to a named location policy

    Why it's wrong here

    Converting the policy to a named location policy changes the condition from device state to network geography (e.g., trusted IPs or countries). A named location policy can only control access based on where the request originates, not whether the endpoint is compliant, patched, or enrolled. This abandons the requirement entirely because it never checks Intune compliance status.

  • ✗

    Remove MFA from all users

    Why it's wrong here

    Removing MFA from all users is a separate, security-regressing change unrelated to device compliance. MFA is another grant control, often applied alongside compliance, but disabling it does not affect the device-compliance condition; the policy will still require a compliant device. More importantly, it weakens identity security and could allow a non-compliant device session to pass if other conditions fail.

  • ✓

    Include the relevant cloud app or target all cloud apps after testing exclusions

    Why this is correct

    A compliant-device policy does not automatically select which cloud apps are protected; you must explicitly add a target resource (cloud app or action) in the policy's assignments. To avoid blanket lockout, start with a pilot group and a specific app like Exchange Online, then expand to 'All cloud apps' with carefully tested exclusions. Without this assignment, the grant control has no app to apply to, so the policy is effectively inert.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.