Courseiva

Device Compliance Policy and Conditional Access for Resource Access

Your organization uses Microsoft Intune for mobile device management and Microsoft Entra ID for identity. You are designing a solution to ensure that only devices that are compliant with security policies can access corporate resources. The requirements are: 1) Devices must have a minimum OS version. 2) Devices must have encryption enabled. 3) Devices must not be jailbroken or rooted. 4) Access to corporate apps must be blocked if the device is non-compliant. 5) The solution should automatically remediate non-compliant devices when possible. You need to recommend the minimum configuration. What should you do?

Quick Answer

The answer is to create a device compliance policy in Intune with the required settings, and create a Conditional Access policy that requires compliant devices. This combination works because the Intune compliance policy defines the security baselines—such as minimum OS version, encryption, and jailbreak detection—while the Conditional Access policy in Microsoft Entra ID enforces the gate, blocking access to corporate resources unless the device is marked compliant. On the Microsoft Cybersecurity Architect exam, this scenario tests your understanding of how device compliance policy and Conditional Access for resource access integrate as a layered defense; a common trap is confusing app protection policies (which protect data at the app level) with device-level compliance enforcement. Remember the memory tip: “Compliance sets the rules, Conditional Access enforces the school.”

⚠ Common exam trap

SC-100 often tests the difference between configuration policies (which set settings) and compliance policies (which assess settings), and candidates may confuse the two or overlook Conditional Access as the enforcement mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a device compliance policy in Intune with the required settings, and create a Conditional Access policy that requires compliant devices.

The minimum configuration is to create a device compliance policy in Intune with the required settings (minimum OS version, encryption, jailbreak/root detection) and create a Conditional Access policy that requires compliant devices. This ensures only compliant devices can access corporate resources, and Intune can automatically remediate non-compliant devices where possible.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure Microsoft Purview Compliance Manager to assess compliance and block access.

    Why it's wrong here

    Microsoft Purview Compliance Manager assesses regulatory posture and produces improvement actions; it neither evaluates device signals nor enforces conditional access blocking. It is tempting because it reports compliance against standards, and would be correct for tracking an organisation's regulatory compliance score rather than gating device access.

  • ✗

    Create an app protection policy in Intune that requires minimum OS and encryption.

    Why it's wrong here

    App protection policies govern app-level data controls such as copy-paste and PIN on enrolled or unenrolled devices; they do not evaluate device OS version, encryption or jailbreak state, nor remediate. It is tempting because app protection policies do block corporate app access, and would be correct for BYOD data-leakage control without device enrolment.

  • ✓

    Create a device compliance policy in Intune with the required settings, and create a Conditional Access policy that requires compliant devices.

    Why this is correct

    An Intune compliance policy enforces the minimum OS version, encryption and jailbreak or root detection requirements, while a Conditional Access policy requiring compliant devices blocks corporate app access for non-compliant devices and supports automatic remediation.

  • ✗

    Create a device configuration policy in Intune for the settings, and use Microsoft Entra ID Protection to block access.

    Why it's wrong here

    A device configuration policy pushes settings but does not itself evaluate compliance or remediate drift, and Entra ID Identity Protection blocks based on sign-in and user risk, not device compliance state. It is tempting because both are Intune and Entra ID controls, and would be correct for deploying configuration baselines or detecting risky sign-ins.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that only devices with a TPM (Trusted Platform Module) version 2.0 can access corporate resources. What should you configure?

medium
  • ✓ A.Create a device compliance policy that requires TPM 2.0 and use Conditional Access to block non-compliant devices
  • B.Use Windows Update for Business to ensure TPM firmware is updated
  • C.Configure device enrollment restrictions to require TPM 2.0
  • D.Deploy a device configuration profile that enables TPM 2.0

Why A: A device compliance policy in Microsoft Intune can check for TPM 2.0 presence and version. When combined with a Conditional Access policy that blocks non-compliant devices, only devices meeting the TPM 2.0 requirement can access corporate resources. This is the correct approach because Conditional Access enforces the compliance check at the authentication and authorization layer.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.