Courseiva
Prepare infrastructure for deviceseasyMultiple ChoiceObjective-mapped

Conditional Access: Require Device to Be Marked as Compliant

You need to ensure that only compliant devices can access corporate email in Exchange Online. Which Conditional Access policy setting should you configure?

Quick Answer

The answer is to configure the Conditional Access setting "Require device to be marked as compliant." This setting ensures that only devices meeting your organization’s compliance policies—such as having up-to-date antivirus or encryption—can access Exchange Online email, directly tying device health to access control. On the MD-102 exam, this scenario tests your understanding of how Conditional Access enforces endpoint compliance before granting resource access, often appearing as a distractor against options like multi-factor authentication or hybrid Azure AD join. A common trap is confusing device identity (hybrid join) with device health (compliance); remember, compliance is about the device’s current security posture, not its directory registration. Memory tip: think "Compliance = Condition for Content" to link the setting to email access.

⚠ Common exam trap

Watch out — candidates often confuse device compliance with device join type (hybrid Azure AD join) or app-level controls, mistakenly thinking that requiring a specific join type or approved app alone ensures the device is healthy and secure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Require device to be marked as compliant

The 'Require device to be marked as compliant' setting in a Conditional Access policy enforces that only devices meeting your organization's compliance policies (e.g., BitLocker enabled, antivirus active, OS version current) can access Exchange Online. This leverages Microsoft Intune device compliance policies and the Microsoft Entra ID device registration state to block non-compliant devices from accessing corporate email.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Require device to be marked as compliant

    Why this is correct

    Directly enforces compliance for access.

  • Require multi-factor authentication

    Why it's wrong here

    MFA is for user authentication, not device compliance.

  • Require hybrid Azure AD joined device

    Why it's wrong here

    Device join status, not compliance.

  • Require approved client app

    Why it's wrong here

    App-level policy, not device compliance.

About these practice questions

This MD-102 question is part of Courseiva's 942-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MD-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You need to ensure that only corporate-owned devices can access Microsoft 365 apps. You plan to use Conditional Access in Microsoft Entra ID. What should you configure as the grant control?

easy
  • A.Require Hybrid Azure AD joined device.
  • B.Require multi-factor authentication.
  • C.Require approved client app.
  • D.Require device to be marked as compliant.

Why D: Conditional Access grant control 'Require device to be marked as compliant' ensures that only devices enrolled in Microsoft Intune and meeting your compliance policies (e.g., encryption, OS version, threat level) can access Microsoft 365 apps. This directly enforces the requirement that only corporate-owned devices are allowed, as compliance status is tied to managed devices. In contrast, other options either don't restrict to corporate-owned devices or address different security concerns.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.