Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your company uses Microsoft Intune to manage corporate devices. You need to design a compliance policy that requires devices to have a minimum OS version, be encrypted, and not be jailbroken or rooted. Additionally, you want to automatically block non-compliant devices from accessing corporate email. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Intune compliance policies and Conditional Access

Intune compliance policies and Conditional Access. Compliance policies in Intune define the specific requirements you listed—minimum OS version, encryption, and jailbreak/root detection—and Conditional Access then enforces those results by blocking non-compliant devices from accessing corporate resources such as Exchange Online email. The other options do not fit: device configuration profiles and Microsoft Entra ID join (B) configure settings and identity but do not evaluate compliance or block access; app protection policies and Defender for Endpoint (C) protect app data and detect threats but do not enforce device compliance for email access; and device enrollment restrictions (D) only control which devices can enroll, not ongoing compliance or access control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Intune compliance policies and Conditional Access

    Why this is correct

    Intune compliance policies assess a device's security posture—such as jailbreak status, OS version, encryption, and threat level from Defender for Endpoint—and generate a compliant/non-compliant state that is stored in Microsoft Entra ID. Conditional Access policies then consume that state at sign-in, using a 'Require device to be marked compliant' grant control to block or allow access to email and other corporate resources. This is the definitive mechanism because it combines continuous health evaluation with identity-driven enforcement, and it works with both Android and iOS device-specific checks like the SafetyNet attestation or Apple's device compliance.

  • ✗

    Device configuration profiles and Microsoft Entra ID join

    Why it's wrong here

    Device configuration profiles are meant to push settings—such as password policies, restrictions, or Wi-Fi configuration—but they do not evaluate a device's health or produce a compliance state that can trigger access decisions. Microsoft Entra ID join is an identity relationship that registers the device in the tenant and is a prerequisite for some Conditional Access policies, but it does not verify whether a device is compromised or out of compliance. Together, they lack the critical health evaluation and real-time enforcement loop, so a joined device with the proper profile can still be jailbroken or outdated and access email.

  • ✗

    App protection policies and Microsoft Defender for Endpoint

    Why it's wrong here

    App protection policies (MAM) are data-loss-prevention controls that operate within individual applications—they can block copy/paste, prevent save-as, or enforce a PIN when a managed app opens, but they are device-agnostic and do not evaluate the underlying OS or its security posture. Microsoft Defender for Endpoint does provide rich endpoint threat telemetry, but that signal must be ingested by a compliance policy via the 'require a threat level' setting before it influences conditional access; Defender alone does not directly block email. This pairing lacks the compliance policy that would translate MDE's risk score into a device-level 'not compliant' verdict.

  • ✗

    Device enrollment restrictions

    Why it's wrong here

    Device enrollment restrictions are an onboarding-time gate—they limit which devices can enroll in Intune based on platform, OS version, or corporate device categories, and they are evaluated only when the device enters management. Once enrolled, a device could be jailbroken, updated to a vulnerable OS, or fail to meet a new policy without any re-evaluation, because enrollment restrictions do not perform continuous health checks or signal to Microsoft Entra ID. Since the goal is to block access after enrollment, this mechanism is too early in the device lifecycle and has no relationship to Conditional Access at the time of a sign-in.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.