Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

You are designing a Zero Trust architecture for a company that uses Microsoft Entra ID and Microsoft Intune. The security team wants to enforce device compliance before granting access to cloud apps. Which policy should you implement?

⚠ Common exam trap

Many exam-takers confuse risk-based policies (Identity Protection) with device compliance policies, assuming any policy that checks 'risk' or 'session' can enforce device health, but only Conditional Access with the compliant device grant control directly ties Intune compliance to access decisions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra Conditional Access policy requiring compliant device

Microsoft Entra Conditional Access policies can require that devices are marked as compliant by Microsoft Intune before granting access to cloud apps. This directly enforces device compliance as a condition for access, which is a core Zero Trust principle of verifying every access request based on device health.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra Identity Protection user risk policy

    Why it's wrong here

    Microsoft Entra Identity Protection user risk policies assess the likelihood that a user's account has been compromised, using signals such as leaked credentials or irregular usage patterns. They respond by forcing password resets or blocking sign-ins based on that user-level risk. However, they do not evaluate any device attributes like OS patch level, encryption status, or compliance with Microsoft Intune policies. As a result, such a policy cannot enforce device compliance and is therefore an incorrect choice for a device-centric zero trust requirement.

  • ✗

    Microsoft Defender for Cloud Apps session policy

    Why it's wrong here

    Microsoft Defender for Cloud Apps session policies are applied through app-enforced conditional access, operating at the proxy layer to control actions within SaaS apps, such as restricting downloads or requiring step-up authentication. They are active only after authentication has succeeded and do not check whether the device is enrolled or compliant with Intune. Device compliance is evaluated by the device management stack, not by the session control proxy. Hence, this does not meet the requirement for device compliance enforcement.

  • ✓

    Microsoft Entra Conditional Access policy requiring compliant device

    Why this is correct

    An Entra Conditional Access policy requiring a compliant device is the correct mechanism because it directly checks the device's compliance state as reported by Microsoft Intune at sign-in time. The policy evaluates device health attributes like encryption, jailbreak status, and threat detection, and can block access or grant access only when compliant. This is the standard zero trust control that enforces device compliance before granting access to applications or resources.

  • ✗

    Microsoft Entra ID Protection sign-in risk policy

    Why it's wrong here

    Microsoft Entra ID Protection sign-in risk policies evaluate the probability that a specific authentication attempt is risky, using real-time signals such as impossible travel or anonymous IP addresses. If a sign-in exceeds the risk threshold, the policy may block the attempt or require Microsoft Entra Multi-Factor Authentication. This approach focuses exclusively on the sign-in event and user identity, not on the device's configuration or compliance status. Consequently, it does not provide device compliance enforcement and is an incorrect answer here.

Go deeper

Related to this question

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.