MS-900 Describe Microsoft 365 apps and services Practice Question
An organization decides to implement Microsoft 365 Business Premium. The security team wants to ensure that all devices accessing company data are compliant with security policies. Which service should they use?
⚠ Common exam trap
MS-900 often tests the confusion between identity management (Entra ID) and device management (Intune), leading candidates to choose Entra ID for device compliance when Intune is the actual enforcement tool.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Intune
Microsoft Intune is the mobile device management (MDM) and mobile application management (MAM) service within Microsoft 365 that enforces compliance policies on devices accessing corporate data. It allows administrators to define security requirements such as PIN, encryption, OS version, and jailbreak/root detection, and then conditionally grant access only to compliant devices. Intune integrates with Microsoft Entra ID to evaluate device compliance during authentication, ensuring that only devices meeting security policies can access company resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Office 365
Why it's wrong here
Microsoft Defender for Office 365 protects email, links and collaboration workloads from phishing and malware; it does not assess device compliance with security policies. It is tempting because it is a security service included in the suite, and would be correct for defending against email-borne threats.
- ✗
Microsoft Entra ID
Why it's wrong here
Microsoft Entra ID handles identity, authentication and conditional access; it does not itself evaluate device compliance against security policies. It is tempting because conditional access can require compliant devices, but the compliance state must be produced by Intune, which is the correct service here.
- ✓
Microsoft Intune
Why this is correct
Microsoft Intune enforces compliance policies, configuration profiles and conditional access on enrolled devices, so only devices meeting security baselines reach company data. It directly satisfies the stem's requirement that all devices accessing organisational data comply with security policies.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview handles data governance, classification and compliance, not device policy enforcement. It cannot evaluate device health or conditional access. The security team needs Intune, which marks devices compliant and feeds that state to Microsoft Entra ID for access decisions.
Go deeper
Related to this question
Learn chapter
Microsoft Teams Rooms and Meeting Devices
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
Key term
MAM
Mobile Application Management (MAM) is a set of technologies and policies that allow IT administrators to manage and secure corporate applications on mobile devices without managing the entire device.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.