SC-100 Design security solutions for infrastructure Practice Question
Your company uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate Exchange Online mailboxes. Which conditional access policy setting should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant: Require device to be marked as compliant.
The correct option is A, Grant: Require device to be marked as compliant, because this conditional access grant control evaluates the device's compliance state reported by Intune and only allows access to Exchange Online when the device meets the assigned compliance policy. This directly enforces the requirement that only compliant devices can reach corporate mailboxes. Option B, Require approved client app, restricts which apps can access the resource but does not verify device compliance. Option C, Require multifactor authentication, strengthens user sign-in verification but does not assess the device's compliance status. Option D, Require Intune enrollment, only ensures the device is managed by Intune, not that it satisfies the compliance policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Grant: Require device to be marked as compliant.
Why this is correct
The 'Require device to be marked as compliant' conditional access grant checks the device's compliance state as reported by Intune via Microsoft Entra ID device registration. Intune evaluates compliance policies (such as OS version, encryption, and threat level) and sets the device state, which Microsoft Entra ID enforces during sign-in. This directly blocks non-compliant devices from accessing resources.
- ✗
Grant: Require approved client app.
Why it's wrong here
Require approved client app is an app-level grant control that validates the client application's identity and ensures an app protection policy is applied, rather than inspecting the underlying device's compliance status. It focuses on securing corporate data at the app layer, such as restricting copy/paste or requiring a PIN, but it does not verify that the device itself is compliant. A non-compliant device with an approved app could still satisfy this grant.
- ✗
Grant: Require multifactor authentication.
Why it's wrong here
Require multifactor authentication strengthens user identity verification by requiring an additional factor like a phone call or authenticator app, but it imposes no conditions on the device's configuration, health, or management status. A device that is non-compliant or even compromised can still pass MFA, because MFA authenticates the user, not the device. This grant cannot enforce Intune compliance.
- ✗
Grant: Require Intune enrollment.
Why it's wrong here
Require Intune enrollment only confirms that the device is a managed device registered with Intune, which is a prerequisite for compliance but not a guarantee. A device can be enrolled yet fail compliance policies due to missing updates, jailbroken OS, or a high threat score from Defender for Endpoint. This grant would allow such non-compliant enrolled devices, whereas 'Require device to be marked as compliant' would block them.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.