Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

An administrator needs to ensure that only compliant devices can access Exchange Online. Which Microsoft Entra ID feature should they configure?

⚠ Common exam trap

MS-900 often tests the distinction between authentication-strengthening features (MFA, Authenticator) and access-decision features (Conditional Access), so candidates who see 'compliant devices' and jump to MFA or Identity Protection pick the wrong control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access policies

Conditional Access policies in Microsoft Entra ID evaluate signals such as user, device compliance state, location, and app, and can grant or block access based on those conditions. To restrict Exchange Online access to compliant devices only, the admin creates a policy targeting Exchange Online that requires the device to be marked compliant (via Intune) or hybrid Microsoft Entra ID joined. This is the specific Entra ID feature designed for signal-based, conditional access enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Privileged Identity Management

    Why it's wrong here

    Privileged Identity Management governs just-in-time activation and approval of privileged directory roles; it does not evaluate device health or compliance. It is tempting because it is an Entra ID governance feature controlling access, but device compliance requires Intune compliance policies surfaced as Conditional Access conditions. Role activation cannot attest to endpoint configuration state.

  • ✓

    Conditional Access policies

    Why this is correct

    Conditional Access policies evaluate device compliance signals from Intune, enforcing grant controls that block or permit access to Exchange Online. This directly satisfies the stem's requirement that only compliant devices connect, since the policy checks the device's compliance state at sign-in and denies access when that condition is unmet.

  • ✗

    Multi-Factor Authentication

    Why it's wrong here

    Multi-Factor Authentication verifies a user's identity with a second factor; it says nothing about the device's compliance with configuration baselines. It is tempting because MFA is a Conditional Access grant control, but device compliance needs a compliance policy evaluated by Intune and enforced through Conditional Access. MFA alone cannot block non-compliant devices.

  • ✗

    Identity Protection

    Why it's wrong here

    Identity Protection detects and remediates risky sign-ins and compromised credentials via risk policies; it evaluates user behaviour, not device compliance state. It is tempting because both are Conditional Access inputs, but device compliance requires a compliance policy plus a Conditional Access grant. Risk signals cannot attest that a device meets configuration baselines.

Go deeper

Related to this question

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.