Courseiva

AZ-500 Secure identity and access Practice Question

You need to ensure that only approved iOS devices can access corporate email. Which Microsoft Intune policy should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Device compliance policy

The correct option is D, Device compliance policy. A compliance policy defines the rules a device must meet (for example, requiring a compliant/approved iOS device state) and, combined with Conditional Access, blocks noncompliant devices from accessing corporate email such as Exchange Online. Enrollment restrictions (A) only control which devices may enroll or which platforms are allowed, not ongoing email access. Device configuration policies (B) push settings to devices but do not gate access, and app protection policies (C) protect app data on enrolled or unenrolled devices without enforcing device-level approval for email access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enrollment restriction

    Why it's wrong here

    In Intune, enrollment restrictions control the initial device onboarding by blocking or allowing platforms and device types at the moment of enrollment. However, they do not continuously re-evaluate a device's identity, model, or iOS version after enrollment, so a once-approved device can later become unauthorized without being flagged. Access control for approved iOS devices requires periodic assessment, which only a compliance policy can provide.

  • ✗

    Device configuration policy

    Why it's wrong here

    A device configuration policy applies settings such as passcode requirements, restrictions, and feature toggles to enrolled iOS devices, but it does not determine whether that device is authorized to access corporate resources. Configuration policies are declarative and static; they do not generate a compliance state or feed Conditional Access decisions. Thus, they cannot enforce that only approved devices can access—they only define how approved devices should be configured.

  • ✗

    App protection policy

    Why it's wrong here

    App protection policies (MAM) safeguard corporate data inside individual apps by applying PIN, encryption, and data-loss-prevention rules at the application layer, even on unmanaged devices. They are not device-level access controls and do not assess whether the underlying iOS device itself is approved for access. For device-level access enforcement, you need a compliance policy that marks the whole device as compliant or noncompliant based on its identity and condition.

  • ✓

    Device compliance policy

    Why this is correct

    A device compliance policy in Microsoft Intune defines the rules that an iOS device must satisfy, such as a minimum OS version, a specific model, or jailbreak detection, and then scores the device as compliant or noncompliant on a regular schedule. This compliance state is consumed by Microsoft Entra Conditional Access to allow or block access to Exchange, SharePoint, and other corporate apps. Therefore, it directly ensures that only approved iOS devices can access—because any device that fails the policy is denied at the time of access.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.