Conditional Access: Require Device to Be Marked as Compliant
You need to ensure that only compliant devices can access corporate email in Exchange Online. Which Conditional Access policy setting should you configure?
Quick Answer
The answer is to configure the Conditional Access setting "Require device to be marked as compliant." This setting ensures that only devices meeting your organization’s compliance policies—such as having up-to-date antivirus or encryption—can access Exchange Online email, directly tying device health to access control. On the MD-102 exam, this scenario tests your understanding of how Conditional Access enforces endpoint compliance before granting resource access, often appearing as a distractor against options like multi-factor authentication or hybrid Azure AD join. A common trap is confusing device identity (hybrid join) with device health (compliance); remember, compliance is about the device’s current security posture, not its directory registration. Memory tip: think "Compliance = Condition for Content" to link the setting to email access.
⚠ Common exam trap
Watch out — candidates often confuse device compliance with device join type (hybrid Azure AD join) or app-level controls, mistakenly thinking that requiring a specific join type or approved app alone ensures the device is healthy and secure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require device to be marked as compliant
The 'Require device to be marked as compliant' setting in a Conditional Access policy enforces that only devices meeting your organization's compliance policies (e.g., BitLocker enabled, antivirus active, OS version current) can access Exchange Online. This leverages Microsoft Intune device compliance policies and the Microsoft Entra ID device registration state to block non-compliant devices from accessing corporate email.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Require device to be marked as compliant
Why this is correct
Directly enforces compliance for access.
- ✗
Require multi-factor authentication
Why it's wrong here
MFA is for user authentication, not device compliance.
- ✗
Require hybrid Azure AD joined device
Why it's wrong here
Device join status, not compliance.
- ✗
Require approved client app
Why it's wrong here
App-level policy, not device compliance.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
About these practice questions
This MD-102 question is part of Courseiva's 942-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MD-102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You need to ensure that only corporate-owned devices can access Microsoft 365 apps. You plan to use Conditional Access in Microsoft Entra ID. What should you configure as the grant control?
easy- A.Require Hybrid Azure AD joined device.
- B.Require multi-factor authentication.
- C.Require approved client app.
- ✓ D.Require device to be marked as compliant.
Why D: Conditional Access grant control 'Require device to be marked as compliant' ensures that only devices enrolled in Microsoft Intune and meeting your compliance policies (e.g., encryption, OS version, threat level) can access Microsoft 365 apps. This directly enforces the requirement that only corporate-owned devices are allowed, as compliance status is tied to managed devices. In contrast, other options either don't restrict to corporate-owned devices or address different security concerns.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.