Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A security administrator needs to ensure that all users accessing Microsoft 365 resources from unmanaged devices are prompted to sign in using multi-factor authentication (MFA) and are blocked from downloading sensitive files. Which conditional access policy should be configured?

⚠ Common exam trap

Candidates often confuse App Protection Policies (MAM) with Conditional Access session controls, not realizing that MAM policies manage app-level data protection without controlling sign-in MFA or blocking downloads based on device compliance, while Conditional Access with session controls can enforce both conditions in a single policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access policy with device compliance and session controls

A Conditional Access policy with device compliance and session controls allows the administrator to require MFA for sign-ins from unmanaged devices and use session controls (e.g., Microsoft Defender for Cloud Apps session policies) to block downloading sensitive files. This policy targets specific conditions (unmanaged devices) and applies granular access controls, meeting both requirements precisely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Require MFA for all users

    Why it's wrong here

    This policy enforces multi-factor authentication at sign-in, but it treats all devices the same: both Intune-compliant corporate devices and personal, unmanaged devices must pass MFA. It does not evaluate device health, enrollment, or compliance state, so a user on a non-compliant personal device can still authenticate with MFA and download sensitive files. Because it lacks conditional access conditions and session controls, it cannot satisfy the requirement to block downloads from unmanaged devices.

  • ✗

    Block access from unknown locations

    Why it's wrong here

    Blocking access from unknown locations relies on IP-based named locations and geopolitical boundaries, not on whether the endpoint is managed or compliant. A user connecting from a known office or home IP on an unmanaged personal device would pass the location check and still be able to access and download sensitive data. It also provides no session-level controls to prevent data exfiltration from a browser or desktop session, so it does not meet the stated requirements.

  • ✗

    App protection policies

    Why it's wrong here

    App protection policies (MAM) govern data handling within mobile applications, such as disabling copy/paste, preventing 'save as,' or controlling access to corporate data in Outlook mobile. However, they are limited to supported mobile apps and do not enforce MFA at the moment of sign-in, nor do they apply to browser-based access to SharePoint/Exchange or desktop apps like Word/Excel. Their focus is mobile app data-loss prevention rather than device-level compliance or conditional access gating, leaving unmanaged browser sessions unprotected.

  • ✓

    Conditional Access policy with device compliance and session controls

    Why this is correct

    A Conditional Access policy can combine a device-compliance condition with grant controls that require MFA only for unmanaged devices, so compliant, Intune-enrolled devices get a smoother sign-in. Once access is granted, session controls—via app control in Microsoft Defender for Cloud Apps—can enforce real-time restrictions such as blocking download or print of sensitive files in the browser or desktop session. This directly addresses both the need to require stronger verification on unmanaged devices and the need to prevent sensitive file downloads, making it the correct answer.

Go deeper

Related to this question

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.