SC-100 Practice Question: Design security operations, identity, and compliance capabilities
A company uses Microsoft Intune to manage devices. They need to ensure that only devices with a minimum OS version can access corporate email. Which policy type should they implement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compliance policies combined with conditional access
Compliance policies combined with conditional access. Compliance policies in Intune define the required conditions a device must meet, such as a minimum OS version, and conditional access in Entra ID enforces those requirements by blocking access to corporate email (for example, Exchange Online) when the device is noncompliant. This combination is the standard way to gate email access on OS version. Device enrollment restrictions (A) only control which devices can enroll or which platforms are allowed, not ongoing OS-version-based access to email. App protection policies (B) protect app data with PINs and encryption but do not enforce a minimum OS version for email access. Device configuration profiles (D) configure settings on devices but do not by themselves block email access based on compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Device enrollment restrictions
Why it's wrong here
Device enrollment restrictions are evaluated only during the enrollment process, meaning they determine which devices can become managed based on platform, OS, or ownership at that single point in time. They do not re-evaluate the device's OS version or compliance status after enrollment, so a device that enrolls while compliant can later drift to an unsupported OS version. Because they never run at the access or sign-in stage, they cannot enforce a minimum OS requirement on an ongoing basis.
- ✗
App protection policies
Why it's wrong here
App protection policies (APP/MAM) govern how users interact with corporate data inside protected applications—such as restricting copy/paste, blocking save to unallowed locations, or requiring a PIN—but they are applied per app, not per device OS. Even when an app is fully protected, the underlying device OS may be older than the required version, and the app will still function as long as its own policy checks pass. Therefore, app protection policies can enforce data-security behaviors but cannot block access solely because the OS version is unsupported.
- ✓
Compliance policies combined with conditional access
Why this is correct
A compliance policy in Intune evaluates a device's health attributes—including whether its OS version meets the minimum required for that platform—and simply marks the device compliant or non-compliant. That compliance status is then consumed by a Conditional Access policy as a grant control, which, at the time of every authentication request, rejects access for non-compliant devices (or requires additional steps like re-enrollment or OS update). This combination is the actual enforcement chain: the compliance policy identifies the OS-version gap, and Conditional Access blocks the user's access accordingly.
- ✗
Device configuration profiles
Why it's wrong here
Device configuration profiles configure device and application settings—such as restrictions, settings like OS limitations, certificates, email, or Wi-Fi—using the device's management channel. These profiles are applied intensions or remediations rather than access-control decisions; they do not evaluate the device’s state during sign-in or prevent a user from accessing a resource on a device that fails to honor them. Even if a profile is configured to enforce a settings baseline, there is no inherent enforcement if a device doesn’t comply, so it cannot replace a compliance-and-Conditional-Access mechanism for OS-version requirements.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.