Courseiva

Set Conditional Access to Require Compliant Device for Access

You are configuring Conditional Access for device compliance. You have an Intune compliance policy that requires a minimum OS version. You create a Conditional Access policy that grants access only when devices are marked as compliant. However, some users can still access corporate email from non-compliant devices. What is the most likely reason?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Conditional Access policy does not include the email application as a target.

A Conditional Access policy must include at least one cloud app as a target. If the corporate email application (e.g., Exchange Online) is not included in the policy, the policy will not apply to access attempts for that app, allowing non-compliant devices to connect. Option A is incorrect because a 'Block' policy would block access, not allow it. Option B is incorrect because the policy's user scope does not affect whether the app is targeted. Option C is incorrect because while compliance policy assignment is important, the most direct reason is the missing app target.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Conditional Access policy is set to 'Block' instead of 'Grant'.

    Why it's wrong here

    A Block policy denies access outright, so non-compliant devices would be stopped, not admitted; the symptom contradicts this setting. Block is the correct control when the requirement is to deny rather than gate access on compliance state.

  • ✗

    The Conditional Access policy applies only to users in a specific group.

    Why it's wrong here

    A group-scoped policy leaves users outside that group unaffected, so their non-compliant devices still reach email. Group targeting is legitimate for phased rollouts or pilot rings, where limiting enforcement to selected users is intentional. Here the symptom spans users beyond the group, so scoping cannot explain universal bypass.

  • ✗

    The compliance policy is not assigned to the users' devices.

    Why it's wrong here

    Compliance policy is assigned to devices, not users.

  • ✓

    The Conditional Access policy does not include the email application as a target.

    Why this is correct

    Conditional Access grants apply only to the cloud apps explicitly targeted, so omitting Exchange Online leaves email unprotected regardless of compliance state. The policy's grant control therefore never evaluates sessions to that resource, satisfying the stem's requirement that non-compliant devices be blocked from corporate email.

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.