SC-100 Practice Question: Design security operations, identity, and compliance capabilities
A company uses Microsoft Intune and wants to ensure that devices are compliant before accessing corporate resources. They create a Conditional Access policy that requires devices to be marked as compliant. However, some users report that they are blocked even though their device shows as compliant in Intune. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The device is not registered in Microsoft Entra ID
The device is not registered in Microsoft Entra ID. Conditional Access evaluates device compliance using the device identity and compliance state that Intune writes back to Microsoft Entra ID, so if the device object is not registered (or not properly joined/registered) in Entra ID, the 'Require device to be marked as compliant' grant control cannot be satisfied even if Intune shows the device as compliant. Options A and B describe other possible blocks (location policy or MFA registration), but they do not explain the mismatch between Intune compliance and Conditional Access blocking. Option D is also not the most likely cause because an app protection policy requirement is a separate grant control and would not typically contradict a device already showing compliant in Intune.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user's location is blocked by a location-based policy
Why it's wrong here
Location conditions in Conditional Access evaluate the user's IP subnet against named locations and, if blocked, would prevent sign-in due to network geography, not due to the device's compliance state. The device compliance grant control is evaluated only after the request passes location checks, and it compares the device's status against the Intune compliance policy. Since the device lacks Microsoft Entra ID registration, the compliance calculation fails regardless of any location rule, so a location-based block is not the cause described here.
- ✗
The policy also requires MFA, and users haven't registered for MFA
Why it's wrong here
MFA registration is enforced as a separate grant control in Conditional Access, and a user's failure to satisfy MFA would produce an MFA-authentication challenge rather than a device compliance failure. The policy in question evaluates device compliance, which relies solely on the device having an identity in Microsoft Entra ID and, through that enrollment, a compliance state from Intune. Even if MFA were fully registered, the device would still be blocked because it is not registered in Entra ID, so the root cause is unrelated to MFA.
- ✓
The device is not registered in Microsoft Entra ID
Why this is correct
For Conditional Access to require a compliant device, the device must have an identity object in Microsoft Entra ID—either through Microsoft Entra join, hybrid join, or enrollment in Intune as a registered device. Intune's compliance policy is applied to that device identity, and the resulting compliance status is stored as an attribute in Entra ID that Conditional Access can read. Without registration, the device is completely invisible to the compliance evaluation, so the policy marks it as not compliant and blocks access.
- ✗
The policy requires an app protection policy, which is not applied
Why it's wrong here
App protection policies (APP) are part of mobile application management and govern data-level behavior inside a managed app; they do not generate or modify the device's compliance state in Microsoft Entra ID. Conditional Access checks for APP as an independent grant control (e.g., 'Require app protection policy'), which is separate from the device compliance condition that assesses the device registration and configuration. Because the device is not registered at all, no compliance state exists for Intune to set, and the absence of an APP cannot be the reason for this failure.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.