Configure Conditional Access to Require Compliant Devices for Email Access
Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate Exchange Online email. Which conditional access policy setting should you use?
Quick Answer
The answer is to configure the Conditional Access policy with the grant control "Require device to be marked as compliant." This setting ensures that only devices meeting your Intune compliance policies—such as requiring encryption, a minimum OS version, or a healthy threat level—can access Exchange Online email. Conditional Access evaluates the device’s compliance status in real time before granting a token, making it the precise control for this scenario. On the MD-102 exam, this question tests your ability to distinguish between compliance-based access and other controls like MFA or app protection policies; a common trap is confusing device enrollment with compliance, but enrollment alone does not enforce health checks. Remember the memory tip: "Compliance is the gatekeeper, enrollment is just the key."
⚠ Common exam trap
MD-102 often tests the confusion between 'Require device to be marked as compliant' and 'Require device to be enrolled' — enrollment alone does not guarantee compliance, and only the compliance grant control enforces policy adherence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require device to be marked as compliant.
To ensure only compliant devices access Exchange Online, the Conditional Access policy must include the grant control 'Require device to be marked as compliant.' This control checks the device's compliance state in Intune and blocks access if the device is non-compliant, directly enforcing the requirement. It is the precise setting for compliance-based access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Require device to be marked as compliant.
Why this is correct
Require device to be marked as compliant makes Microsoft Entra ID conditional access grant Exchange Online access only when Intune reports the device compliant. It directly satisfies the stem's constraint that only compliant devices reach corporate email.
- ✗
Require multi-factor authentication.
Why it's wrong here
MFA verifies the strength of user authentication, not the health or configuration state of the device, so an unmanaged or non-compliant device still gains access. It is tempting because MFA hardens sign-in; it would be correct when the requirement is to confirm user identity rather than device compliance.
- ✗
Require app protection policy.
Why it's wrong here
App protection policies govern data handling within mobile apps on unenrolled devices and do not assert device compliance. It is tempting because it protects corporate data on personal devices; it would be correct when you must secure app-level data without requiring device enrolment or compliance.
- ✗
Require device to be enrolled in Intune.
Why it's wrong here
Enrolment confirms device registration and management, not that it satisfies your compliance policies, so a non-compliant enrolled device still passes. It is tempting because enrolment precedes compliance evaluation; it would be correct when you must restrict access to managed devices regardless of their current compliance state.
Go deeper
Related to this question
Learn chapter
Configuring Compliance Policies
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
Conditional Access policy
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MD-102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. You configure a Conditional Access policy in Microsoft Entra ID targeting Exchange Online. What else must you configure in Intune to enforce compliance?
medium- ✓ A.Device compliance policies.
- B.No additional configuration is needed.
- C.Device configuration policies.
- D.App protection policies.
Why A: A is correct because Conditional Access policies in Microsoft Entra ID evaluate device compliance status, but they rely on Intune to report that status. Without a device compliance policy assigned to the device, Intune cannot mark the device as compliant, so the Conditional Access policy will block access or treat the device as non-compliant. You must create and assign a compliance policy in Intune that defines the required security baselines (e.g., encryption, OS version, jailbreak detection) for the device to be considered compliant.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.