SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Entra ID and Microsoft Intune. You need to design a solution that allows corporate users to access a sensitive internal application only from managed devices that are compliant with company security policies. The solution should block access from personal devices. Which two components should you use? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Intune device compliance policy
Option D (Microsoft Intune device compliance policy) is correct because it defines and evaluates the security requirements—such as BitLocker, OS version, and firewall settings—that a device must meet to be marked compliant, which is the foundation for gating access to the sensitive application. Option E (Microsoft Entra ID Conditional Access policy that requires a compliant device) is correct because Conditional Access enforces the access decision at authentication time, granting access only when Intune reports the device as compliant and blocking personal or non-compliant devices. Together, the compliance policy determines device state and the Conditional Access policy enforces it for the target app. Option A is not correct because app protection policies (MAM) protect app data on unmanaged/personal devices rather than blocking access from them. Option B is not correct because requiring hybrid Microsoft Entra ID join restricts access to domain-joined devices and does not directly enforce the company's compliance policy baseline. Option C is not correct because device enrollment alone only registers devices in Intune; without a compliance policy and Conditional Access enforcement, it does not block personal or non-compliant devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Intune app protection policy
Why it's wrong here
Microsoft Intune app protection policies (APP) are data-loss-prevention controls that operate at the application layer. They enforce behavior such as preventing copy/paste or requiring a PIN within a specific app, but they do not evaluate the device's overall compliance state or block access at the device level. Therefore, APP alone cannot be used to verify that a device meets your organization's security requirements before granting access to corporate resources.
- ✗
Microsoft Entra ID Conditional Access policy that requires hybrid Microsoft Entra ID join
Why it's wrong here
Requiring hybrid Microsoft Entra ID join in Conditional Access only identifies devices that are joined to an on-premises AD and registered with Entra ID, which is a valid managed-device signal for Windows endpoints. However, it is not a compliance assessment: it does not check whether the device has the latest OS update, BitLocker enabled, or a compliant configuration, and it is not designed for personally owned devices or mobile platforms. A Conditional Access policy that requires a compliant device is more flexible because it can combine multiple compliance signals from Intune.
- ✗
Microsoft Intune device enrollment
Why it's wrong here
Microsoft Intune device enrollment is the process of registering a device into management so that IT can deploy configurations, certificates, and compliance policies to it. While enrollment is a necessary prerequisite for device compliance evaluation and policy-based access control, the act of enrollment alone does not grant or revoke access to Exchange, SharePoint, or other cloud apps. Real-time access decisions are made by Conditional Access, which consumes the compliance status that results from enrolled devices being assessed against compliance policies.
- ✓
Microsoft Intune device compliance policy
Why this is correct
A Microsoft Intune device compliance policy defines the exact security and configuration standards that a device must meet to be considered compliant, such as requiring encryption, a minimum OS version, no jailbreak/root, or a healthy threat agent score. The policy assigns a compliance state (compliant/non-compliant) for each enrolled device, and that state is then published to Entra ID. This policy is the foundation of device-based access control because it establishes the authoritative criteria that determine whether a device should be trusted.
- ✓
Microsoft Entra ID Conditional Access policy that requires a compliant device
Why this is correct
An Entra ID Conditional Access policy that requires a compliant device enforces access control by checking the device's compliance state as reported by Intune and then either allowing, blocking, or requiring additional verification before a user can access an app. It is the enforcement layer that turns the compliance state into an access decision, and it can be scoped to specific apps, users, and conditions. This policy is correct because without such a Conditional Access grant control, a compliant device status alone does not actively secure any cloud resource.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.