AZ-500 Manage identity and access Practice Question
A company wants to ensure that users can only access Microsoft 365 services (e.g., Exchange Online, SharePoint Online) from devices that are confirmed to be compliant with corporate security policies (e.g., encryption enabled, antivirus active). Which Microsoft Entra ID policy type should they create?
⚠ Common exam trap
A common mix-up: candidates confuse device compliance (Conditional Access) with sign-in risk (Identity Protection), as both involve 'risk' or 'compliance' terminology but target fundamentally different aspects of security—device state versus authentication risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policy with the 'Require compliant device' grant control.
A is correct because a Conditional Access policy with the 'Require compliant device' grant control enforces device-based access restrictions by checking the device's compliance status reported by Microsoft Intune. This ensures that only devices meeting corporate security policies (e.g., encryption enabled, antivirus active) can access Microsoft 365 services like Exchange Online and SharePoint Online.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access policy with the 'Require compliant device' grant control.
Why this is correct
This grant control is enforced by Microsoft Entra ID during authentication after Intune evaluates the device state; if the device is not enrolled in Mobile Device Management or fails compliance checks (such as missing encryption, a detected jailbreak, or a threat from Microsoft Defender for Endpoint), sign-in is blocked. Because the policy runs in real time on every authentication request, it precisely meets the requirement that users can only access Microsoft 365 services from devices that meet your organization's security baseline. It can also target specific cloud apps and the Microsoft 365 suite, and you can combine it with session controls for additional security.
- ✗
Identity Protection policy with a sign-in risk policy.
Why it's wrong here
A sign-in risk policy in Identity Protection consumes risk signals like impossible travel, anonymous IP addresses, or unfamiliar sign-in properties and responds with actions such as requiring multi-factor authentication or blocking the attempt. These signals are not device compliance indicators, and a device that is compromised yet somehow risk-scored low would still be permitted through even if it is out of compliance. Identity Protection also supports risk-based Conditional Access policies, but the integration still does not evaluate Intune compliance or device health state; it only decides how much authentication assurance the user's risk level currently justifies.
- ✗
Access review policy for groups.
Why it's wrong here
Access reviews focus on lifecycle governance: administrators or delegated reviewers periodically reconfirm whether a user still belongs to a group or retains an application assignment, with the result being automatic removal from the group or application when approval is denied. This is a manual, periodic attestation process typically scheduled weekly, monthly, or quarterly, so it cannot block a non-compliant device at the point of sign-in. Even if a review revoked access, it would do so based on membership decisions, not on real-time device compliance signals, making it unsuitable for device-based access control.
- ✗
Privileged Identity Management (PIM) activation policy.
Why it's wrong here
PIM activation policies are scoped to privileged roles in Microsoft Entra ID, Azure resources, and sometimes Microsoft 365 administrative roles, and they control how elevated access is granted via time-bound activation, approval workflows, and additional authentication checks. These policies apply only when a user attempts to activate an elevated role, not when a user signs in to access ordinary Microsoft 365 services like Exchange Online or SharePoint, and they have no awareness of device compliance. PIM focuses on least privilege for administrators, leaving regular user access and device health entirely outside its enforcement scope.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.