Courseiva

Device Compliance and Hybrid Azure AD Join for Conditional Access

Your organization uses Microsoft Entra ID and Microsoft Intune. You need to design a solution that allows only hybrid Microsoft Entra ID joined devices to access a sensitive application. The solution must also require that the device is compliant with company policies. Which two components should you configure? (Choose TWO.)

Quick Answer

This design needs two separate grant controls because the scenario is asking for two different guarantees at once: proof of what the device is, and proof of what state the device is in. A Conditional Access policy with the 'Require hybrid Azure AD joined device' control answers the identity question — it only allows access from devices that are joined to both the on-premises Active Directory and Microsoft Entra ID, which is the specific device type the scenario names. An Intune device compliance policy answers the state question separately, evaluating the device against defined security requirements like disk encryption or OS version and marking it compliant or not; Conditional Access can then reference that compliance status as its own grant control. Neither control substitutes for the other: a hybrid-joined device that fails compliance still shouldn't get in, and a compliant device that isn't hybrid-joined doesn't satisfy the device-type requirement either. It's worth distinguishing this pairing from an Intune app protection policy, which secures data inside a specific app regardless of overall device state, and from device enrollment, which is the prerequisite that lets Intune manage the device at all but isn't itself an access control. When a scenario names both a device type and a compliance requirement, expect both a device-join grant control and a compliance policy in the answer.

⚠ Common exam trap

SC-100 often tests whether candidates confuse device compliance with device join state or MFA, leading them to select app protection policies or MFA-only Conditional Access when the requirement explicitly demands hybrid join and compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access policy with 'Require hybrid Microsoft Entra ID joined device'

Option C is correct because a Conditional Access policy with the 'Require hybrid Microsoft Entra ID joined device' grant control enforces that only devices registered as hybrid Microsoft Entra ID joined can access the sensitive application, directly satisfying the device-trust requirement. Option E is correct because an Intune device compliance policy defines and evaluates the rules (such as OS version, encryption, and password requirements) that determine whether a device is compliant, and Conditional Access can then require a compliant device. Together, C and E let Conditional Access grant access only when the device is both hybrid Microsoft Entra ID joined and compliant. Option A is not correct because Intune app protection policies (MAM) protect app data on mobile devices and do not enforce hybrid Microsoft Entra ID join or device compliance for Conditional Access. Option B is not correct because requiring multifactor authentication verifies the user, not the device's join state or compliance. Option D is not correct because device enrollment merely onboards devices into Intune; it does not itself enforce the hybrid join or compliance requirements at access time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Intune app protection policy

    Why it's wrong here

    App protection policies safeguard corporate data within mobile apps on unmanaged devices, so they do not verify hybrid Microsoft Entra ID join or device compliance for application access. They are tempting because they protect sensitive data on personal devices, which is the correct scenario for BYOD without enrolment.

  • ✗

    Conditional Access policy with 'Require multifactor authentication'

    Why it's wrong here

    Multifactor authentication verifies the user's identity, not the device's join state or compliance, so it cannot enforce the hybrid Microsoft Entra ID joined and compliant device conditions. It is tempting because MFA is the usual Conditional Access control for protecting sensitive applications against credential compromise.

  • ✓

    Conditional Access policy with 'Require hybrid Microsoft Entra ID joined device'

    Why this is correct

    A Conditional Access policy targeting the sensitive application with the 'Require hybrid Microsoft Entra ID joined device' grant control blocks every device lacking that join state, satisfying the hybrid-only constraint at authentication time. Combined with a compliance requirement, it enforces both conditions before a token is issued.

  • ✗

    Intune device enrollment

    Why it's wrong here

    Enrolling devices in Intune establishes management but does not itself grant or restrict access, so it cannot enforce the hybrid join and compliance requirements at the application. It is tempting because enrolment is the prerequisite step that makes devices manageable and compliance policies assignable.

  • ✓

    Intune device compliance policy

    Why this is correct

    An Intune device compliance policy evaluates each device against your configured rules, such as encryption, OS version and firewall settings, and reports a compliant or non-compliant state to Microsoft Entra ID. Conditional Access then reads that signal, satisfying the requirement that only policy-compliant devices reach the sensitive application.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Entra ID and Microsoft Intune. You need to design a solution that allows corporate users to access a sensitive internal application only from managed devices that are compliant with company security policies. The solution should block access from personal devices. Which two components should you use? (Choose TWO.)

hard
  • A.Microsoft Intune app protection policy
  • B.Microsoft Entra ID Conditional Access policy that requires hybrid Azure AD join
  • C.Microsoft Intune device enrollment
  • ✓ D.Microsoft Intune device compliance policy
  • ✓ E.Microsoft Entra ID Conditional Access policy that requires a compliant device

Why D: Option D (Microsoft Intune device compliance policy) is correct because it defines and evaluates the security requirements—such as BitLocker, OS version, and firewall settings—that a device must meet to be marked compliant, which is the foundation for gating access to the sensitive application. Option E (Microsoft Entra ID Conditional Access policy that requires a compliant device) is correct because Conditional Access enforces the access decision at authentication time, granting access only when Intune reports the device as compliant and blocking personal or non-compliant devices. Together, the compliance policy determines device state and the Conditional Access policy enforces it for the target app. Option A is not correct because app protection policies (MAM) protect app data on unmanaged/personal devices rather than blocking access from them. Option B is not correct because requiring hybrid Azure AD join restricts access to domain-joined devices and does not directly enforce the company's compliance policy baseline. Option C is not correct because device enrollment alone only registers devices in Intune; without a compliance policy and Conditional Access enforcement, it does not block personal or non-compliant devices.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.