Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

Your organization wants to ensure that users can only access Microsoft 365 resources from compliant devices. Which security feature should you implement?

⚠ Common exam trap

MS-900 often tests the confusion between Intune (which sets compliance state) and Conditional Access (which enforces access based on that state) — candidates pick Intune when the question asks what enforces the restriction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra Conditional Access

Microsoft Entra Conditional Access is the policy engine that evaluates signals such as device compliance state, user risk, location, and application, and then enforces access decisions like requiring a compliant device or MFA. To restrict Microsoft 365 access to compliant devices, you create a Conditional Access policy that requires the device to be marked compliant (a signal Intune provides). Conditional Access is the enforcement point; Intune supplies the compliance signal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Entra Conditional Access

    Why this is correct

    Microsoft Entra Conditional Access evaluates signals such as device compliance state and enforces access controls, blocking sign-ins from non-compliant devices. This directly satisfies the requirement that users reach Microsoft 365 resources only from compliant devices, which Intune alone cannot enforce at authentication.

  • ✗

    Microsoft Purview Data Loss Prevention

    Why it's wrong here

    Microsoft Purview Data Loss Prevention inspects and blocks sensitive content in Exchange, SharePoint, Teams and endpoints; it does not evaluate device compliance state. Conditional Access in Microsoft Entra ID is what grants or denies Microsoft 365 access based on whether the device is compliant.

  • ✗

    Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps provides discovery, anomaly detection and session controls for cloud apps, but it does not gate Microsoft 365 sign-in on device compliance. Conditional Access in Microsoft Entra ID performs that enforcement using the Intune compliance signal.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune manages device configuration and compliance policies, but enforcing that only compliant devices reach Microsoft 365 requires a Conditional Access policy in Microsoft Entra ID that evaluates the device compliance signal at sign-in. Intune alone supplies the signal, not the access gate.

Go deeper

Related to this question

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.