MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
Your organization wants to ensure that users can only access Microsoft 365 resources from compliant devices. Which security feature should you implement?
⚠ Common exam trap
MS-900 often tests the confusion between Intune (which sets compliance state) and Conditional Access (which enforces access based on that state) — candidates pick Intune when the question asks what enforces the restriction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Conditional Access
Microsoft Entra Conditional Access is the policy engine that evaluates signals such as device compliance state, user risk, location, and application, and then enforces access decisions like requiring a compliant device or MFA. To restrict Microsoft 365 access to compliant devices, you create a Conditional Access policy that requires the device to be marked compliant (a signal Intune provides). Conditional Access is the enforcement point; Intune supplies the compliance signal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra Conditional Access
Why this is correct
Microsoft Entra Conditional Access evaluates signals such as device compliance state and enforces access controls, blocking sign-ins from non-compliant devices. This directly satisfies the requirement that users reach Microsoft 365 resources only from compliant devices, which Intune alone cannot enforce at authentication.
- ✗
Microsoft Purview Data Loss Prevention
Why it's wrong here
Microsoft Purview Data Loss Prevention inspects and blocks sensitive content in Exchange, SharePoint, Teams and endpoints; it does not evaluate device compliance state. Conditional Access in Microsoft Entra ID is what grants or denies Microsoft 365 access based on whether the device is compliant.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps provides discovery, anomaly detection and session controls for cloud apps, but it does not gate Microsoft 365 sign-in on device compliance. Conditional Access in Microsoft Entra ID performs that enforcement using the Intune compliance signal.
- ✗
Microsoft Intune
Why it's wrong here
Microsoft Intune manages device configuration and compliance policies, but enforcing that only compliant devices reach Microsoft 365 requires a Conditional Access policy in Microsoft Entra ID that evaluates the device compliance signal at sign-in. Intune alone supplies the signal, not the access gate.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Security Center
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.