MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A security administrator needs to ensure that all users accessing Microsoft 365 resources from unmanaged devices are prompted to sign in using multi-factor authentication (MFA) and are blocked from downloading sensitive files. Which conditional access policy should be configured?
⚠ Common exam trap
Candidates often confuse App Protection Policies (MAM) with Conditional Access session controls, not realizing that MAM policies manage app-level data protection without controlling sign-in MFA or blocking downloads based on device compliance, while Conditional Access with session controls can enforce both conditions in a single policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policy with device compliance and session controls
A Conditional Access policy with device compliance and session controls allows the administrator to require MFA for sign-ins from unmanaged devices and use session controls (e.g., Microsoft Defender for Cloud Apps session policies) to block downloading sensitive files. This policy targets specific conditions (unmanaged devices) and applies granular access controls, meeting both requirements precisely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require MFA for all users
Why it's wrong here
This policy enforces multi-factor authentication at sign-in, but it treats all devices the same: both Intune-compliant corporate devices and personal, unmanaged devices must pass MFA. It does not evaluate device health, enrollment, or compliance state, so a user on a non-compliant personal device can still authenticate with MFA and download sensitive files. Because it lacks conditional access conditions and session controls, it cannot satisfy the requirement to block downloads from unmanaged devices.
- ✗
Block access from unknown locations
Why it's wrong here
Blocking access from unknown locations relies on IP-based named locations and geopolitical boundaries, not on whether the endpoint is managed or compliant. A user connecting from a known office or home IP on an unmanaged personal device would pass the location check and still be able to access and download sensitive data. It also provides no session-level controls to prevent data exfiltration from a browser or desktop session, so it does not meet the stated requirements.
- ✗
App protection policies
Why it's wrong here
App protection policies (MAM) govern data handling within mobile applications, such as disabling copy/paste, preventing 'save as,' or controlling access to corporate data in Outlook mobile. However, they are limited to supported mobile apps and do not enforce MFA at the moment of sign-in, nor do they apply to browser-based access to SharePoint/Exchange or desktop apps like Word/Excel. Their focus is mobile app data-loss prevention rather than device-level compliance or conditional access gating, leaving unmanaged browser sessions unprotected.
- ✓
Conditional Access policy with device compliance and session controls
Why this is correct
A Conditional Access policy can combine a device-compliance condition with grant controls that require MFA only for unmanaged devices, so compliant, Intune-enrolled devices get a smoother sign-in. Once access is granted, session controls—via app control in Microsoft Defender for Cloud Apps—can enforce real-time restrictions such as blocking download or print of sensitive files in the browser or desktop session. This directly addresses both the need to require stronger verification on unmanaged devices and the need to prevent sensitive file downloads, making it the correct answer.
Go deeper
Related to this question
Learn chapter
Cross-Tenant Access Policies in Entra ID
Key term
Conditional Access policy
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.