Integrating Microsoft Intune with Entra ID for Device Compliance and Conditional Access
Your company is designing a Zero Trust network for a hybrid workforce. Remote users connect via VPN to on-premises resources, while cloud apps use Microsoft Entra ID. You need to enforce conditional access based on device compliance and user risk. Which Microsoft security solution should you integrate with Entra ID to provide real-time device posture signals?
Quick Answer
The answer is Microsoft Intune, as it is the correct Microsoft security solution to integrate with Entra ID for enforcing conditional access based on device compliance and user risk. Intune provides device compliance policies that assess real-time posture signals—such as encryption status, patch levels, and threat detection—and feeds these signals directly into Entra ID Conditional Access policies. This integration allows you to block or grant access to cloud apps and VPN-connected resources based on whether a device meets your compliance standards, which is a core requirement for a Zero Trust hybrid workforce. On the Microsoft Cybersecurity Architect exam, this scenario tests your understanding of how device management (Intune) plugs into identity-driven access control (Entra ID), a common trap is confusing Intune with Defender for Cloud Apps or Sentinel, which handle CASB and SIEM functions respectively. Memory tip: think of Intune as the “bouncer” checking the device’s health at the door, while Entra ID is the “ID checker” for the user—both must work together for Zero Trust.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Intune
Microsoft Intune provides device compliance policies and can send device posture signals to Entra ID Conditional Access. With Intune, you can enforce device health and compliance requirements before granting access. Option A is wrong because Microsoft Purview focuses on data governance and compliance, not device management. Option C is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) and does not directly manage device compliance. Option D is wrong because Microsoft Sentinel is a security information and event management (SIEM) solution and does not provide device posture signals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview is a data governance solution and does not enforce device compliance or provide device posture signals for Conditional Access.
- ✓
Microsoft Intune
Why this is correct
Correct. Microsoft Intune manages device compliance policies and integrates with Entra ID Conditional Access to enforce access based on device compliance and user risk.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps is a CASB that provides cloud app visibility and controls, but it does not directly manage device compliance or provide device posture signals to Entra ID.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a SIEM/SOAR for security analytics and threat detection, not a device management solution for Conditional Access.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your company is planning to use Microsoft Intune for mobile device management (MDM). You need to ensure that devices are compliant before accessing corporate resources. Which TWO components should you configure?
easy- A.Device configuration policies.
- B.Enrollment restrictions.
- ✓ C.Conditional Access policies in Microsoft Entra ID.
- ✓ D.Compliance policies.
- E.App protection policies.
Why C: Conditional Access policies in Microsoft Entra ID (option C) enforce access controls based on device compliance, while Compliance policies (option D) define the conditions for device compliance. Together, they ensure only compliant devices can access corporate resources. Option A (Device configuration policies) are for settings, not compliance. Option B (Enrollment restrictions) control which devices can enroll, not post-enrollment compliance. Option E (App protection policies) manage app-level data protection, not device compliance.
Variation 2. Your company uses Microsoft Intune to manage devices. You need to ensure that corporate data is wiped from a device if it reports a jailbroken status. What is the best approach?
medium- ✓ A.Create a device compliance policy that marks jailbroken devices as noncompliant, then use Conditional Access to require compliance
- B.Use the remote wipe action from Intune when a jailbreak is reported
- C.Deploy an app protection policy that wipes data if jailbreak is detected
- D.Configure a device configuration policy to block jailbroken devices
Why A: A device compliance policy can mark jailbroken devices as noncompliant, and Conditional Access can then enforce a wipe or block access, ensuring automatic remediation. Option B is incorrect because remote wipe is a manual action and does not automatically respond to compliance status. Option C is incorrect because app protection policies target app data, not the entire device. Option D is incorrect because device configuration policies do not trigger conditional access or automatic wipe.
Variation 3. Your company uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate Exchange Online mailboxes. Which conditional access policy setting should you configure?
easy- ✓ A.Grant: Require device to be marked as compliant.
- B.Grant: Require approved client app.
- C.Grant: Require multifactor authentication.
- D.Grant: Require Intune enrollment.
Why A: The 'Require device to be marked as compliant' grant control in Conditional Access ensures that only devices meeting your Intune compliance policies can access Exchange Online. Option B (Require approved client app) is for app protection policies, not device compliance. Option C (Require multifactor authentication) addresses authentication strength, not compliance. Option D (Require Intune enrollment) ensures enrollment but not the compliance state itself; a device can be enrolled yet non-compliant.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.