Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

A company uses Microsoft 365 Business Premium and wants to enable secure remote access for employees using personal devices. Which Microsoft 365 app should they configure to enforce conditional access policies based on device compliance?

⚠ Common exam trap

Candidates often confuse Microsoft Defender for Cloud Apps (a CASB) with device compliance enforcement, but Defender for Cloud Apps controls app access via session policies, not device health checks, which is Intune's role.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Intune

Microsoft Intune is the correct answer because it is the Microsoft 365 app that provides mobile device management (MDM) and mobile application management (MAM). It allows administrators to define device compliance policies (e.g., requiring encryption, PIN, or a minimum OS version) and integrate those policies with Microsoft Entra ID (formerly Azure AD) Conditional Access. When a user attempts to access corporate resources from a personal device, Conditional Access checks the device's compliance status reported by Intune before granting access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Purview

    Why it's wrong here

    Microsoft Purview is a data governance and compliance solution, not a tool for enforcing conditional access policies based on device compliance. It lacks the policy engine and device identity integration required to evaluate device health or block access from non-compliant personal devices. The option is tempting because Purview handles security-related tasks such as data loss prevention and information protection, which might appear relevant to securing remote access. However, the correct technology for this scenario is Microsoft Entra ID, which directly manages conditional access policies by assessing device compliance status through integration with Microsoft Intune.

  • ✓

    Microsoft Intune

    Why this is correct

    Microsoft Intune is the correct answer because it serves as the mobile device management (MDM) and mobile application management (MAM) service that enrolls devices, applies compliance policies (such as requiring encryption, OS versions, or jailbreak detection), and reports each device's compliance status to Microsoft Entra ID. Entra ID then uses that status as a condition in Conditional Access policies to grant or block access. Without Intune, there is no authoritative source for device health and no way to enforce access restrictions based on device compliance.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) solution that ingests logs and telemetry from across your environment to detect threats, investigate incidents, and enable security analytics. It does not own or manage device compliance data, nor does it integrate with Entra ID Conditional Access to evaluate device health in real time. While Sentinel can collect compliance-related logs for monitoring, it cannot block access or make access decisions based on device compliance—that is Intune's role.

  • ✗

    Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps is a CASB (Cloud Access Security Broker) that gives visibility into cloud SaaS usage, applies data loss prevention and session controls, and detects anomalous behavior in third-party apps. It does not evaluate device compliance or report device health to Entra ID; its Conditional Access app control works as a session policy to enforce restrictions after access has been granted, rather than as a pre-authentication gate based on device posture. Thus, it is not the technology that integrates with Intune for device compliance-based conditional access.

Go deeper

Related to this question

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.