Conditional Access: Require Device to Be Marked as Compliant
You need to ensure that only compliant devices can access corporate email in Exchange Online. Which Conditional Access policy setting should you configure?
Quick Answer
The answer is to configure the Conditional Access setting "Require device to be marked as compliant." This setting ensures that only devices meeting your organization’s compliance policies—such as having up-to-date antivirus or encryption—can access Exchange Online email, directly tying device health to access control. On the MD-102 exam, this scenario tests your understanding of how Conditional Access enforces endpoint compliance before granting resource access, often appearing as a distractor against options like multi-factor authentication or hybrid Azure AD join. A common trap is confusing device identity (hybrid join) with device health (compliance); remember, compliance is about the device’s current security posture, not its directory registration. Memory tip: think "Compliance = Condition for Content" to link the setting to email access.
⚠ Common exam trap
Watch out — candidates often confuse device compliance with device join type (hybrid Microsoft Entra ID join) or app-level controls, mistakenly thinking that requiring a specific join type or approved app alone ensures the device is healthy and secure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require device to be marked as compliant
The 'Require device to be marked as compliant' setting in a Conditional Access policy enforces that only devices meeting your organization's compliance policies (e.g., BitLocker enabled, antivirus active, OS version current) can access Exchange Online. This leverages Microsoft Intune device compliance policies and the Microsoft Entra ID device registration state to block non-compliant devices from accessing corporate email.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Require device to be marked as compliant
Why this is correct
Requiring the device to be marked as compliant enforces Intune compliance state at token issuance, so Exchange Online blocks mail access from non-compliant devices. This directly satisfies the stem's constraint that only compliant devices reach corporate email, since Microsoft Entra ID evaluates the device's compliance status during sign-in.
- ✗
Require multi-factor authentication
Why it's wrong here
Require multi-factor authentication strengthens sign-in assurance but says nothing about device health state. A non-compliant device could still pass MFA and reach Exchange Online. Device compliance requires the require compliant device grant control, which queries Intune compliance status.
- ✗
Require hybrid Microsoft Entra ID joined device
Why it's wrong here
Require hybrid Microsoft Entra joined device checks domain join state, not compliance with configuration baselines. A joined device can still be non-compliant. The require compliant device control evaluates Intune compliance policy results, which is what the scenario demands.
- ✗
Require approved client app
Why it's wrong here
Require approved client app restricts access to apps supporting Intune app protection policies, which is app-level data protection, not device compliance. Requiring a compliant device is the setting that enforces compliance. Approved client app suits BYOD scenarios where device enrolment is unwanted.
Go deeper
Related to this question
Learn chapter
Deploying Applications with Intune
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
About these practice questions
This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MD-102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You need to ensure that only corporate-owned devices can access Microsoft 365 apps. You plan to use Conditional Access in Microsoft Entra ID. What should you configure as the grant control?
easy- A.Require Hybrid Azure AD joined device.
- B.Require multi-factor authentication.
- C.Require approved client app.
- ✓ D.Require device to be marked as compliant.
Why D: Conditional Access grant control 'Require device to be marked as compliant' ensures that only devices enrolled in Microsoft Intune and meeting your compliance policies (e.g., encryption, OS version, threat level) can access Microsoft 365 apps. This directly enforces the requirement that only corporate-owned devices are allowed, as compliance status is tied to managed devices. In contrast, other options either don't restrict to corporate-owned devices or address different security concerns.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.