Your organization has Windows 11 devices used by remote employees. You need to ensure that only devices compliant with your security policies can access corporate email via Microsoft Outlook for Windows. What should you configure?
Trap 1: Set up a device compliance policy in Microsoft Purview to block…
Microsoft Purview governs data classification and labelling, not device access enforcement. Conditional Access in Microsoft Entra ID evaluates Intune compliance state before granting Outlook access. Purview compliance policies would be the right tool for auditing or protecting sensitive content, not for gating email sign-in by device health.
Trap 2: Configure a device filter in Exchange Online to block devices that…
Exchange Online device filters act on ActiveSync device attributes for mobile mailbox access, not on Intune-managed Windows 11 compliance signals. Conditional Access is what enforces device compliance for Outlook. Exchange device rules would be correct for blocking specific phone models or unmanaged ActiveSync clients.
Trap 3: Deploy an email security policy via Intune to block access from…
An Intune email security policy controls mail flow, attachments and encryption settings; it does not evaluate device compliance or block Outlook access. Such policies suit data-loss prevention within email. Conditional Access enforces compliance before granting access to Exchange Online.
- A
Set up a device compliance policy in Microsoft Purview to block non-compliant devices.
Why it fails: Microsoft Purview governs data classification and labelling, not device access enforcement. Conditional Access in Microsoft Entra ID evaluates Intune compliance state before granting Outlook access. Purview compliance policies would be the right tool for auditing or protecting sensitive content, not for gating email sign-in by device health.
- B
Create a Conditional Access policy in Microsoft Entra ID that requires device compliance, and assign the policy to the cloud app 'Office 365 Exchange Online'.
Conditional Access evaluates sign-in signals and, with a device compliance grant control, blocks non-compliant Windows 11 devices from Office 365 Exchange Online. Assigning the policy to that cloud app restricts Outlook access specifically, meeting the compliance requirement.
- C
Configure a device filter in Exchange Online to block devices that are not managed by Intune.
Why it fails: Exchange Online device filters act on ActiveSync device attributes for mobile mailbox access, not on Intune-managed Windows 11 compliance signals. Conditional Access is what enforces device compliance for Outlook. Exchange device rules would be correct for blocking specific phone models or unmanaged ActiveSync clients.
- D
Deploy an email security policy via Intune to block access from non-compliant devices.
Why it fails: An Intune email security policy controls mail flow, attachments and encryption settings; it does not evaluate device compliance or block Outlook access. Such policies suit data-loss prevention within email. Conditional Access enforces compliance before granting access to Exchange Online.