MS-900 Describe Microsoft 365 apps and services Practice Question
A user reports that they cannot access their email on their mobile device. The IT administrator suspects a device compliance issue. Which Microsoft 365 service can the administrator use to check the device's compliance status?
⚠ Common exam trap
Many candidates confuse the Microsoft Purview compliance portal (which handles regulatory compliance and data protection) with device compliance (which is a mobile device management function handled exclusively by Intune).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Intune
Microsoft Intune is the correct tool because it is the mobile device management (MDM) and mobile application management (MAM) component of Microsoft 365. It allows administrators to define compliance policies (e.g., requiring encryption, a minimum OS version, or a healthy device attestation) and then check a device's compliance status in real time. When a device is non-compliant, Intune can block access to corporate resources like email, which matches the user's reported issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Purview compliance portal
Why it's wrong here
Microsoft Purview compliance portal is the wrong choice because it is a compliance and data governance solution, not a device management or access-control plane. Its capabilities—such as data classification, retention policies, eDiscovery, and audit logs—address legal and regulatory requirements, but they do not evaluate device health, enforce encryption, or check that a device meets compliance policies before granting email access. While Purview can receive signals from other services, it cannot perform the real-time device compliance checks that block access to email when a device is noncompliant.
- ✓
Microsoft Intune
Why this is correct
Microsoft Intune is the correct answer because it is the service that manages device compliance and integrates with Conditional Access in Microsoft Entra ID. Intune collects health and configuration signals—such as OS version, jailbreak/root status, encryption, and threat-defense status—and marks a device as compliant or noncompliant. When a user tries to access email on a mobile device, Exchange Online consults Conditional Access, which checks the device's compliance state from Intune and blocks access if the device does not meet policy. This is exactly the mechanism that would prevent a noncompliant device from reaching email.
- ✗
Microsoft Exchange admin center
Why it's wrong here
The Microsoft Exchange admin center is incorrect because it is designed to manage mailboxes, mail flow, transport rules, and recipient objects within Exchange Online, not to enforce device compliance for cloud-managed devices. Although EAC has legacy Exchange ActiveSync mailbox policies that can restrict some mobile devices, those policies are not the same as modern Intune device compliance policies and do not provide the granular health checks, conditional access integration, or support for Android, iOS, Windows, and macOS that Intune offers. A user's inability to access email due to device noncompliance is remediated through device policies, not by changing mailbox settings in EAC.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps is not the right solution because it is a cloud access security broker (CASB) that focuses on shadow IT discovery, cloud app risk assessment, session controls, and data protection policies for cloud applications. While it can enforce access controls through app-conditional access and can block risky sessions, it does not perform device compliance evaluation on its own; it consumes device trust signals from Intune and Microsoft Entra ID to make access decisions. The user's email access problem is due to a device compliance failure, which is managed natively by Intune—Defender for Cloud Apps is not the enforcement point for device health.
Go deeper
Related to this question
Learn chapter
MFA and Conditional Access in M365
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.