Courseiva

MS-700 Configure and Manage a Teams Environment Practice Question

You are the Teams administrator for a company that uses Microsoft 365. The security team wants to ensure that only devices that are compliant with Intune compliance policies can access Microsoft Teams. All users are licensed for Microsoft 365 E5 and have Intune enrolled devices. You need to configure a conditional access policy that applies specifically to the Microsoft Teams cloud app and requires compliant devices. Which of the following should you do?

⚠ Common exam trap

The trap here is assuming that Teams admin center policies or Intune configuration profiles can enforce device compliance for app access, when conditional access is the only mechanism that evaluates device compliance at sign-in.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In the Microsoft Entra admin center, create a new conditional access policy, assign it to all users, select the Microsoft Teams cloud app, and under Access controls, require the device to be marked as compliant.

The security team requires that only compliant devices access Microsoft Teams. Conditional access in Microsoft Entra ID is the correct tool to enforce device compliance for specific cloud apps. By targeting the Microsoft Teams cloud app and requiring compliant devices, you ensure that only Intune-compliant devices can access Teams, while other apps remain unaffected. Meeting policies, Intune configuration profiles, and sensitivity labels do not provide this level of access control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    In the Microsoft 365 admin center, create a new sensitivity label with encryption settings and apply it to all Teams sites, then require the label for access.

    Why it's wrong here

    Sensitivity labels with encryption protect data at rest and in transit, but they do not enforce device compliance for accessing Teams. They are used for information protection and cannot block access based on device health. This option confuses data protection with access control based on device state, and does not meet the requirement.

  • ✗

    In the Microsoft Teams admin center, create a new meeting policy and set 'Require compliant devices' to On, then assign the policy to all users.

    Why it's wrong here

    Meeting policies in the Teams admin center control features within meetings, such as who can present or use chat, but they do not enforce device compliance for accessing Teams. Device compliance is enforced through conditional access in Microsoft Entra ID, not through Teams meeting policies. This option misidentifies the correct administrative interface and policy type.

  • ✗

    In the Microsoft Intune admin center, create a device compliance policy and assign it to all devices, then create a configuration profile that blocks Teams on noncompliant devices.

    Why it's wrong here

    Intune compliance policies define the rules for device compliance, but they do not by themselves block access to Teams. A configuration profile can restrict device settings, but it cannot enforce conditional access to a cloud app. The requirement is to block access based on compliance, which requires a conditional access policy that evaluates device compliance state.

  • ✓

    In the Microsoft Entra admin center, create a new conditional access policy, assign it to all users, select the Microsoft Teams cloud app, and under Access controls, require the device to be marked as compliant.

    Why this is correct

    This is the correct approach because conditional access policies in Microsoft Entra ID can target the Microsoft Teams cloud app specifically. By requiring the device to be marked as compliant, only devices that meet Intune compliance policies will be granted access. This enforces the security team's requirement without affecting other applications. The policy must be scoped to the Teams cloud app to avoid unintended impact on other services.

About these practice questions

One of 211 original MS-700 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-700 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-700 exam.