PL-300 Manage and secure Power BI Practice Question
Your organization uses Microsoft Intune to manage devices. You need to ensure that Power BI reports can only be viewed on managed devices that are compliant with company policies. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policy in Microsoft Entra ID requiring device compliance.
A Conditional Access policy in Microsoft Entra ID requiring device compliance. Conditional Access is the mechanism that evaluates signals such as Intune device compliance state and enforces access controls, so a policy targeting the Power BI cloud app with a 'Require device to be marked as compliant' grant control ensures reports can only be viewed from managed, compliant devices. Option A is not a real Power BI Premium capacity setting for this purpose, and Power BI capacity settings do not enforce device compliance. Option C only enforces Entra ID authentication for the tenant and does not check device compliance or management state. Option D, an Intune MAM policy, protects app data on mobile devices but does not gate access to Power BI reports based on device compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Power BI Premium capacity setting 'Restrict access to mobile devices'.
Why it's wrong here
Power BI Premium capacities expose settings for workload management, memory limits, and refresh behavior, but there is no setting named 'Restrict access to mobile devices' anywhere in the capacity or Power BI admin portal. Even if a similar restriction existed, capacity-level configuration cannot evaluate device compliance or enforce Intune compliance policies—those are identity and device management functions. This option is invalid because the setting simply does not exist, and any mobile-device restriction must be implemented through Microsoft Entra ID Conditional Access.
- ✓
Conditional Access policy in Microsoft Entra ID requiring device compliance.
Why this is correct
A Conditional Access policy in Microsoft Entra ID is the correct mechanism to block Power BI from non-compliant devices. The policy can require a device to be marked as 'Compliant' by Microsoft Intune before allowing access; this evaluation happens at sign-in time using signals from Intune. For example, the grant control 'Require device to be marked as compliant' combined with the Power BI cloud app will deny access to devices that do not meet your organization's compliance policies. This is the standard and supported way to enforce device-based access control for Power BI.
- ✗
Power BI tenant setting 'Require users to sign in with Microsoft Entra ID'.
Why it's wrong here
The Power BI tenant setting 'Require users to sign in with Microsoft Entra ID' merely mandates that users authenticate using an Entra ID identity, which is already a prerequisite for any Power BI interaction—it does not inspect the device's compliance state. Authentication alone ensures the user is who they say they are, but it does not evaluate whether the device is jailbroken, missing updates, or otherwise non-compliant with Intune policy. Therefore, this setting cannot satisfy a requirement to block non-compliant mobile devices, because it never checks device health or enrollment.
- ✗
Mobile app management (MAM) policy in Microsoft Intune.
Why it's wrong here
A Mobile App Management (MAM) policy in Intune focuses on protecting app-level data, such as requiring a PIN, preventing data transfer to unmanaged apps, or blocking 'Save As'—it does not evaluate device compliance. MAM can apply to both enrolled and unenrolled devices, and it deliberately ignores the broader device state to allow BYOD scenarios. Since this requirement is explicitly about blocking access from non-compliant devices, MAM alone is insufficient; it protects the app and its data but does not verify the device's compliance status. In fact, a non-compliant device could still access Power BI if only MAM is applied, because MAM does not enforce device-level restrictions.
Go deeper
Related to this question
About these practice questions
One of 524 original PL-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.