Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your company has a Microsoft 365 E5 subscription and uses Microsoft Entra ID. You need to configure a conditional access policy that blocks access from devices that are not compliant with your organization's device compliance policies, as defined by Microsoft Intune. Which assignment should you configure in the policy?

⚠ Common exam trap

Many exam-takers confuse 'device compliance' with 'hybrid Microsoft Entra ID join' or 'MFA', assuming any of those controls enforce device health, but only the 'Require device to be marked as compliant' grant directly uses Intune's compliance evaluation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant > Require device to be marked as compliant

The 'Require device to be marked as compliant' grant control in a Conditional Access policy enforces access decisions based on the compliance status reported by Microsoft Intune. When a device is marked as non-compliant by Intune (e.g., missing required updates or having an unapproved app), the policy blocks access. This directly meets the requirement to block devices that do not meet the organization's device compliance policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grant > Require hybrid Microsoft Entra ID joined device

    Why it's wrong here

    Hybrid Microsoft Entra ID joined device only indicates that the device is joined to on-prem Active Directory and synchronized to Microsoft Entra ID. It does not validate device health, configuration, or compliance with Intune policies. Conditional access needs to check the actual compliance status, not just the join type.

  • ✗

    Grant > Require multifactor authentication

    Why it's wrong here

    Requiring multifactor authentication (MFA) verifies the user's identity but does not assess the device's compliance status. MFA cannot enforce device encryption, OS patch levels, or jailbreak detection, which are essential for security compliance. Thus, it only addresses authentication strength, not device trust.

  • ✓

    Grant > Require device to be marked as compliant

    Why this is correct

    Requiring the device to be marked as compliant evaluates the actual compliance status reported by Intune. This ensures the device meets organizational policies, such as OS version, disk encryption, and threat level. It is the precise control for enforcing device compliance in Conditional Access.

  • ✗

    Grant > Require approved client app

    Why it's wrong here

    The approved client app condition is used for app-based conditional access, requiring clients to support app protection policies, like Microsoft Outlook or Teams. It does not evaluate the device's compliance state or enforce Intune compliance policies. Therefore, it supports app-level controls, not device compliance.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.