SC-100 Practice Question: Design security operations, identity, and compliance capabilities
An organization uses Microsoft Intune to manage devices. They need to ensure that only devices compliant with security baselines can access corporate email via Microsoft Outlook. The solution should use existing Microsoft 365 security features. What should they implement?
⚠ Common exam trap
Many candidates confuse device compliance policies (which only define rules) with Conditional Access policies (which enforce access decisions), leading them to pick Option C without realizing a separate policy is needed to block access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy in Microsoft Entra ID that requires compliant device.
Conditional Access policies in Microsoft Entra ID evaluate device compliance status before granting access to cloud apps like Exchange Online. By requiring a compliant device, the policy enforces that only devices meeting security baselines can access corporate email via Outlook, leveraging existing Microsoft 365 identity and access management capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure an app protection policy in Microsoft Intune.
Why it's wrong here
App protection policies (also known as MAM policies) apply data-protection controls to individual applications, such as requiring a PIN, encrypting app data, or preventing copy-and-paste operations. They do not assess the overall device's compliance status and do not act as an authentication or sign-in gate in Microsoft Entra ID. Therefore, even if an app protection policy is applied, a non-compliant device could still access corporate resources; it lacks the enforcement mechanism to block access based on device health.
- ✓
Create a Conditional Access policy in Microsoft Entra ID that requires compliant device.
Why this is correct
A Conditional Access policy in Microsoft Entra ID that includes the 'Require device to be marked as compliant' grant control is the direct integration point with Intune compliance. During authentication, Entra ID evaluates the device's compliance status and blocks sign-in if the device is non-compliant or not enrolled in Intune. This policy is the actual enforcement layer that translates the Intune compliance assessment into an access decision, making it the correct solution to block access from non-compliant devices.
- ✗
Create a device compliance policy in Microsoft Intune.
Why it's wrong here
A device compliance policy in Intune defines rules and evaluates devices to produce a compliance status (compliant or non-compliant), but it is only a background assessment mechanism. It does not intercept or deny authentication requests; the compliance status remains a data point unless some other system consumes it. Without a Conditional Access policy that references the compliance status as a grant control, a non-compliant device will still be allowed to access resources, so the compliance policy alone cannot block access.
- ✗
Configure a device configuration profile in Microsoft Intune.
Why it's wrong here
A device configuration profile in Intune is used to push device settings and management capabilities, such as email configuration, Wi-Fi profiles, certificates, or device restrictions. It focuses on configuring the device and does not evaluate security posture or integrate with Entra ID sign-in decisions. Since it has no direct link to conditional access or compliance assessment, it cannot enforce any access blocking based on device compliance or manage device-level access control.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.