Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A security team wants Microsoft 365 access to be allowed only when a user's device is marked compliant by management policy. Which two capabilities are normally combined? (Choose two.)

⚠ Common exam trap

Many exam-takers confuse Microsoft Intune compliance policies with device management enrollment, forgetting that Conditional Access is the enforcement engine that actually gates access based on the compliance signal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Intune compliance policies

Microsoft Intune compliance policies define the rules that a device must meet (e.g., encryption, OS version, threat level) to be considered compliant. Conditional Access enforces access decisions based on signals like device compliance status, blocking or granting access to Microsoft 365 services. Together, they ensure only compliant devices can access corporate resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Stream

    Why it's wrong here

    Microsoft Stream is a video hosting and sharing service, not a security or access control component. It stores and streams recordings and has no mechanism to evaluate device health or enforce conditional entry to Microsoft 365. Relying on Stream would do nothing to limit access to compliant devices, so it is incorrect.

  • ✓

    Microsoft Intune compliance policies

    Why this is correct

    Microsoft Intune compliance policies define the actual hardware and software requirements that devices must meet—such as OS version, encryption, jailbreak/root status, and threat level—before they are considered compliant. These policies evaluate each enrolled device and assign a compliance state that downstream access controls can consume. This is the component that establishes what 'allowed only' means in terms of device health, making it the right answer.

  • ✗

    Microsoft Forms

    Why it's wrong here

    Microsoft Forms is a lightweight survey and form-building application used to collect user input, not evaluate device posture. It offers no capabilities for checking compliance status or blocking access to Microsoft 365 services based on device attributes. Selecting Forms would ignore the core requirement of restricting access to compliant devices, so it is incorrect.

  • ✓

    Conditional Access

    Why this is correct

    Conditional Access acts as the gatekeeper that uses identity and device signals—including the compliance state reported by Intune—to grant, block, or require additional verification for Microsoft 365 access. It can enforce the outcome of compliance evaluations by denying sessions from non-compliant devices, which is why it is a correct piece of the solution. However, it needs Intune compliance policies to provide the underlying device-health rules to evaluate.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.