SC-100 Design security solutions for infrastructure Practice Question
A multinational corporation uses Microsoft Entra ID for identity and Microsoft Defender for Cloud Apps for SaaS app governance. The security team wants to deploy a conditional access policy that blocks access from untrusted locations for all cloud apps except Microsoft 365, which should only be blocked if the device is not compliant. How should you configure the policy?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create two conditional access policies: one for all cloud apps except Microsoft 365 blocking untrusted locations, and one for Microsoft 365 requiring compliant device.
Option B is correct because Conditional Access policies apply to either all cloud apps or specific apps, and Microsoft 365 cannot be excluded from one policy while having different conditions applied within the same policy. The scenario requires two separate policies: one targeting all cloud apps with Microsoft 365 excluded that blocks untrusted locations, and a second targeting Microsoft 365 that requires a compliant device. Option A is wrong because Defender for Cloud Apps session policies monitor or control sessions but do not block sign-ins from untrusted locations. Option C is wrong because a single policy cannot apply a compliant-device requirement only to Microsoft 365 while including all other cloud apps with different conditions. Option D is wrong because it blocks Microsoft 365 from untrusted locations unconditionally, ignoring the compliant-device exception.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a session policy in Defender for Cloud Apps to monitor non-compliant devices.
Why it's wrong here
Defender for Cloud Apps session policies are designed to monitor and control sessions in real time using app or OU controls, but they are not an access-gate mechanism; they do not evaluate device compliance or block a sign-in before a session begins. Conditional Access policies are the correct enforcement point to reject access based on location or device state. A session policy that merely 'monitors' non-compliant devices provides visibility only and fails to enforce the required block.
- ✓
Create two conditional access policies: one for all cloud apps except Microsoft 365 blocking untrusted locations, and one for Microsoft 365 requiring compliant device.
Why this is correct
Create two separate Conditional Access policies to achieve the required granularity. The first policy targets 'All cloud apps' but excludes Microsoft 365 and uses the 'Block' grant control for untrusted locations, preventing access to non-Microsoft 365 apps from risky networks. The second policy targets Microsoft 365 and requires a compliant device, allowing compliant devices to reach M365 even from untrusted locations. Since the policies are evaluated separately, they cooperate to enforce distinct requirements per app group.
- ✗
Create one conditional access policy that includes all cloud apps and requires compliant device for Microsoft 365 only.
Why it's wrong here
A single Conditional Access policy cannot apply different grant controls to different included applications. If you include 'All cloud apps' and configure 'Require compliant device' as the grant, that same requirement is applied to every app in scope, including Microsoft 365. To enforce a compliant-device requirement only for Microsoft 365, you must create a policy exclusively targeting Microsoft 365, leaving other apps untouched by that control.
- ✗
Configure a conditional access policy that blocks access from untrusted locations for all apps.
Why it's wrong here
Blocking access from untrusted locations for all apps indiscriminately denies Microsoft 365 to users on compliant devices who happen to be in an untrusted location. The desired outcome explicitly allows compliant devices to access Microsoft 365 regardless of location, so this blanket location block is too coarse. Excluding Microsoft 365 from the location-based block—and handling that app with a separate device-compliance policy—is what makes the two-policy approach correct.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.