Courseiva
mediumMultiple Choice

MS-102 Practice Question: Block access to Exchange Online from devices that…

A company wants to block access to Exchange Online from devices that are not compliant with Intune compliance policies. Which Conditional Access grant control should be used?

⚠ Common exam trap

Watch out — candidates often confuse 'Require device to be marked as compliant' with 'Require approved client app' or 'Require MFA', thinking any of these can block non-compliant devices, but only the device compliance grant directly evaluates Intune compliance policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Require device to be marked as compliant

To block access to Exchange Online from non-compliant devices, you need to enforce a Conditional Access policy that evaluates device compliance status. The 'Require device to be marked as compliant' grant control checks the device's compliance state reported by Microsoft Intune before granting access. If the device is not compliant, access to Exchange Online is blocked, ensuring only managed and compliant devices can connect.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Require device to be marked as compliant

    Why this is correct

    This grant control checks a device's Intune compliance status before allowing access to Exchange Online. Non-compliant devices, such as unmanaged or jailbroken devices, are blocked even if the user's credentials are valid. It is the correct choice because it directly enforces the requirement that only devices meeting your organization's security policies can access the service.

  • ✗

    Require MFA

    Why it's wrong here

    Require MFA forces a user to prove their identity with a second factor, but it does not evaluate any property of the endpoint device. A user could satisfy MFA from an unpatched, rooted, or otherwise non-compliant device and still access Exchange Online. Therefore, while MFA strengthens authentication, it does not block access based on device compliance.

  • ✗

    Require approved client app

    Why it's wrong here

    Require approved client app limits access to designated apps like Microsoft Outlook that support app protection policies, but it does not inspect the device's compliance or health state. A device can run an approved app and be simultaneously non-compliant (e.g., missing OS updates or lacking device encryption). Thus this control only restricts the application surface, not the device itself.

  • ✗

    Require all conditions

    Why it's wrong here

    Require all conditions is not an existing grant control in Conditional Access; the actual options are individual grant controls such as MFA, compliant device, and approved client app. The 'all' or 'one' selection is just a toggle that applies to the controls you separately choose. Because it does not represent a specific requirement by itself, this option cannot be used to block non-compliant devices.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.