AZ-500 Secure identity and access Practice Question
Your company uses Microsoft Entra ID (P2 licensed) and requires that all user logins from untrusted networks be blocked unless the user's device is marked as compliant by Microsoft Intune. You need to implement this requirement. Which TWO components should you use together to achieve this? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policy with device compliance condition
Option C is correct because a Conditional Access policy is the mechanism in Microsoft Entra ID that enforces access decisions at sign-in; you configure it with conditions (for example, 'All locations' or 'Any location' excluding trusted named locations) and grant controls requiring a compliant device, so logins from untrusted networks are blocked unless the device meets the compliance requirement. Option D is correct because Microsoft Intune Device Compliance policy defines what 'compliant' actually means (for example, BitLocker enabled, minimum OS version, Defender/antivirus active, no jailbreak/root), and it sets the device's compliance state in Entra ID that the Conditional Access policy evaluates. Together, the Intune compliance policy produces the device compliance signal and the Conditional Access policy consumes it to block non-compliant devices from untrusted networks. Option A (PIM) is for just-in-time privileged role activation and approval, not for device-based sign-in blocking. Option B (Identity Protection) detects and responds to risky users/sign-ins but does not itself enforce device compliance. Option E (Access Reviews) is for periodic attestation of group, role, or application access, not for real-time conditional access enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Privileged Identity Management (PIM)
Why it's wrong here
Privileged Identity Management (PIM) is designed to manage just-in-time and time-bound activation of privileged roles, such as Global Administrator, with approval workflows and multi-factor authentication requirements. It does not evaluate the compliance state of the device attempting to access resources, nor does it inspect any network or location signals. Since the goal is to enforce device compliance from untrusted networks, PIM is not the correct component because it addresses elevated access governance, not device trust enforcement.
- ✗
Microsoft Entra Identity Protection
Why it's wrong here
Microsoft Entra Identity Protection uses machine-learning signals to detect and respond to identity risk events, such as leaked credentials, impossible travel, and suspicious sign-in behavior. It can trigger risk-based policies, like requiring MFA or blocking risky sign-ins, but it does not assess or enforce device compliance attributes such as BitLocker status, OS patch level, or jailbreak detection. The decision to grant access is based on risk, not on whether the device is enrolled and compliant, so it cannot serve as the enforcement point for device compliance.
- ✓
Conditional Access policy with device compliance condition
Why this is correct
A Conditional Access policy with the "Require device to be marked as compliant" condition is the actual enforcement mechanism that blocks or grants access based on the device's current compliance status. When a user attempts to access a cloud app from an untrusted network, the policy combines location and device compliance conditions to deny access if the device is not marked compliant, or grant it if the device is compliant. This policy evaluates the compliance state in real time, using data supplied by Intune, and is the direct control that enforces the requirement.
- ✓
Microsoft Intune Device Compliance policy
Why this is correct
Microsoft Intune Device Compliance policy defines the specific compliance criteria that a device must meet to be considered trusted, such as requiring encryption, a minimum OS version, a healthy threat agent, and no jailbreak/rooting. These policies are not access-control mechanisms themselves; they simply mark the device as compliant or non-compliant in the Microsoft Entra ID directory. Conditional Access then consumes this compliance attribute as a condition, so without the Intune compliance policy, there would be no meaningful device state for Conditional Access to evaluate.
- ✗
Microsoft Entra Access Reviews
Why it's wrong here
Microsoft Entra Access Reviews are designed for periodic recertification of user access to groups, applications, and privileged roles, ensuring that access remains appropriate over time. They are administrative workflows that rely on human reviewers and scheduled attestation, not real-time evaluation of device compliance or network location. Because they do not integrate with Intune compliance signals or enforce policies during authentication, they cannot satisfy the requirement to block non-compliant devices from untrusted networks.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.