Design solutions that align with security best practices and priorities →mediumMultiple ChoiceObjective-mapped
Use Intune Compliance Policy to Require Specific Operating System Version
A company is using Microsoft Intune to manage devices. They need to ensure that only devices with a specific operating system version can access corporate resources. Which Intune policy should they use?
Quick Answer
The answer is a compliance policy. This is correct because Intune compliance policies are specifically designed to enforce rules on managed devices, including requiring a specific operating system version, and when a device fails to meet these rules, it is marked non-compliant; Conditional Access then blocks that device from accessing corporate resources, creating a direct enforcement chain for operating system version access control. On the Microsoft Cybersecurity Architect exam, this concept tests your understanding of how compliance policies and Conditional Access work together as a layered security model, and a common trap is confusing compliance policies with device configuration profiles—remember, configuration profiles *set* settings, but compliance policies *require* and *enforce* them. A useful memory tip is to think of compliance policies as the "bouncer" checking ID (OS version) at the door, while Conditional Access is the locked gate that only opens for approved guests.
⚠ Common exam trap
Test-takers frequently confuse the purpose of Compliance policies (which enforce ongoing access rules based on device health) with Enrollment restrictions (which only gate initial enrollment) or Device configuration policies (which apply settings but do not evaluate compliance).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compliance policy
Compliance policies in Microsoft Intune define the rules that devices must meet to be considered compliant, such as requiring a specific operating system version. When a device is marked non-compliant, Conditional Access policies can block access to corporate resources. This directly enforces the requirement that only devices with the correct OS version can access company data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
App protection policy
Why it's wrong here
App protection policies apply to apps, not device OS version.
- ✗
Enrollment restriction
Why it's wrong here
Enrollment restrictions block devices during enrollment, but do not continuously enforce OS version.
- ✓
Compliance policy
Why this is correct
Compliance policies enforce OS version requirements to grant access.
- ✗
Device configuration policy
Why it's wrong here
Configuration policies set settings but do not enforce compliance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 208 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses Microsoft Intune to manage devices. They want to ensure that only devices that have passed health attestation can access corporate email. Which method should they use?
medium- A.Use Microsoft Defender for Endpoint to block devices that fail health attestation
- ✓ B.Create a device compliance policy for health attestation and use Conditional Access to require compliant devices
- C.Create an app protection policy to require device health attestation
- D.Create a device configuration policy to enforce health attestation
Why B: It combines a device compliance policy that evaluates health attestation (e.g., BitLocker status, Secure Boot, code integrity) with a Conditional Access policy that grants access to corporate email only when the device is marked as compliant. This is the standard Microsoft approach for enforcing health attestation before granting access to cloud resources like Exchange Online.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.