SC-100 Practice Question: Design solutions that align with security best practices and priorities
You are designing a Zero Trust architecture for a company that uses Microsoft Entra ID and Microsoft Intune. The security team wants to enforce device compliance before granting access to cloud apps. Which policy should you implement?
⚠ Common exam trap
Many exam-takers confuse risk-based policies (Identity Protection) with device compliance policies, assuming any policy that checks 'risk' or 'session' can enforce device health, but only Conditional Access with the compliant device grant control directly ties Intune compliance to access decisions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Conditional Access policy requiring compliant device
Microsoft Entra Conditional Access policies can require that devices are marked as compliant by Microsoft Intune before granting access to cloud apps. This directly enforces device compliance as a condition for access, which is a core Zero Trust principle of verifying every access request based on device health.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra Identity Protection user risk policy
Why it's wrong here
Microsoft Entra Identity Protection user risk policies assess the likelihood that a user's account has been compromised, using signals such as leaked credentials or irregular usage patterns. They respond by forcing password resets or blocking sign-ins based on that user-level risk. However, they do not evaluate any device attributes like OS patch level, encryption status, or compliance with Microsoft Intune policies. As a result, such a policy cannot enforce device compliance and is therefore an incorrect choice for a device-centric zero trust requirement.
- ✗
Microsoft Defender for Cloud Apps session policy
Why it's wrong here
Microsoft Defender for Cloud Apps session policies are applied through app-enforced conditional access, operating at the proxy layer to control actions within SaaS apps, such as restricting downloads or requiring step-up authentication. They are active only after authentication has succeeded and do not check whether the device is enrolled or compliant with Intune. Device compliance is evaluated by the device management stack, not by the session control proxy. Hence, this does not meet the requirement for device compliance enforcement.
- ✓
Microsoft Entra Conditional Access policy requiring compliant device
Why this is correct
An Entra Conditional Access policy requiring a compliant device is the correct mechanism because it directly checks the device's compliance state as reported by Microsoft Intune at sign-in time. The policy evaluates device health attributes like encryption, jailbreak status, and threat detection, and can block access or grant access only when compliant. This is the standard zero trust control that enforces device compliance before granting access to applications or resources.
- ✗
Microsoft Entra ID Protection sign-in risk policy
Why it's wrong here
Microsoft Entra ID Protection sign-in risk policies evaluate the probability that a specific authentication attempt is risky, using real-time signals such as impossible travel or anonymous IP addresses. If a sign-in exceeds the risk threshold, the policy may block the attempt or require Microsoft Entra Multi-Factor Authentication. This approach focuses exclusively on the sign-in event and user identity, not on the device's configuration or compliance status. Consequently, it does not provide device compliance enforcement and is an incorrect answer here.
Go deeper
Related to this question
Learn chapter
Designing IoT and Operational Technology Security Architecture
Key term
Microsoft 365 Security Design
Microsoft 365 Security Design is the process of planning and configuring built-in security features in Microsoft 365 to protect data, identities, and devices from cyber threats.
Key term
Zero Trust Strategy
A security model that requires continuous verification of every user, device, and connection before granting access to any resource, regardless of where the request originates.
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.