Courseiva
Secure identity and access →mediumMultiple Choice

AZ-500 Secure identity and access Practice Question

Your company uses Microsoft Intune for mobile device management. You need to ensure that only devices that are compliant with company policies can access corporate resources. You have configured compliance policies in Intune. What additional step is required to enforce access control based on device compliance?

⚠ Common exam trap

Watch out — candidates often assume Intune compliance policies alone enforce access control, but they only define the rules; Conditional Access is the separate service that actually enforces the block or grant based on those rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Conditional Access policy that requires device to be marked as compliant

A is correct because Conditional Access in Microsoft Entra ID is the policy engine that enforces access control decisions based on signals like device compliance. Even after Intune compliance policies are configured, you must create a Conditional Access policy that requires the device to be marked as compliant. This policy blocks or grants access to corporate resources (e.g., Exchange Online, SharePoint) based on the compliance state reported by Intune to Microsoft Entra ID.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a Conditional Access policy that requires device to be marked as compliant

    Why this is correct

    A Conditional Access policy that requires a device to be marked as compliant works directly with Microsoft Intune's compliance policies. When a device fails to meet compliance rules (e.g., PIN required, OS version, threat level), Intune marks it as non-compliant, and Conditional Access evaluates this state at sign-in to block access to cloud apps. This is the standard enforcement mechanism for Intune-managed devices.

  • ✗

    Enable certificate-based authentication for all devices

    Why it's wrong here

    Enabling certificate-based authentication changes how a user proves their identity—for instance, using a smart card or device certificate—but it does not evaluate whether the device is compliant with Intune policies. It is an authentication method, not an access-control enforcement point, so it would not solve the requirement to block non-compliant devices. In fact, CBA can be combined with Conditional Access, but the compliance check would still be handled by Conditional Access.

  • ✗

    Deploy device configuration profiles to all devices

    Why it's wrong here

    Device configuration profiles push settings to devices such as Wi-Fi configuration, email profiles, or encryption requirements, but they do not block access to corporate resources when a device is out of compliance. Compliance policies, on the other hand, define the rules that determine a device's compliant status; a configuration profile alone never changes that status. While both are Intune features, only the compliance evaluation feeds into Conditional Access.

  • ✗

    Configure app protection policies in Microsoft Defender for Cloud Apps

    Why it's wrong here

    App protection policies (APPs) are an Intune feature that manages how data inside apps is handled (e.g., prevent copy/paste, require PIN) and they can apply even to unenrolled devices. The option says 'Microsoft Defender for Cloud Apps,' which is incorrect—Defender for Cloud Apps provides reverse-proxy Conditional Access App Control, not APP. Neither APP nor Defender for Cloud Apps policies directly enforce device compliance; they protect data at the app layer rather than blocking devices based on compliance state.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.