Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft Intune for mobile device management. You need to ensure that only compliant devices can access corporate email. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Conditional Access policy in Microsoft Entra ID that requires compliant device.

Conditional Access in Microsoft Entra ID can enforce device compliance for access. Option A is incorrect because app protection policies protect data within apps but do not control device-level access. Option B is incorrect because device configuration policies define settings but do not enforce compliance-based access. Option D is incorrect because device compliance policies define compliance requirements, but Conditional Access is needed to enforce them.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure an app protection policy in Intune.

    Why it's wrong here

    App protection policies govern data handling within apps on enrolled and unenrolled devices, not whether a device itself meets compliance. They cannot gate email access on device health. They suit BYOD scenarios protecting corporate data inside managed apps without device enrolment.

  • ✗

    Create a device configuration policy in Intune.

    Why it's wrong here

    Device configuration policies push settings to devices, such as Wi-Fi profiles or restrictions, but do not evaluate compliance state. Conditional access policies enforce the compliant-device requirement for email. Configuration policies are correct when you need to apply settings, not authorise access.

  • ✓

    Create a Conditional Access policy in Microsoft Entra ID that requires compliant device.

    Why this is correct

    Conditional Access enforces the compliance signal from Intune at authentication time, so only devices meeting your compliance policy obtain a token for Exchange Online. This directly satisfies the requirement that solely compliant devices reach corporate email, blocking unmanaged or non-compliant endpoints.

  • ✗

    Create a device compliance policy in Intune.

    Why it's wrong here

    A device compliance policy only evaluates and reports device state; it cannot itself block email access. Conditional Access is the enforcement mechanism that grants or denies resource access based on compliance signals. Compliance policies are the correct choice when you need to define and measure the rules, such as encryption or OS version, that Conditional Access then acts upon.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

4 more ways this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Intune for mobile device management. Employees report they cannot access corporate email on their personal iOS devices. The helpdesk confirms devices are enrolled and compliant. What should you check first?

easy
  • A.Confirm the device configuration profile includes email settings.
  • ✓ B.Verify the conditional access policy for Exchange Online includes iOS devices.
  • C.Review the app protection policy for Outlook.
  • D.Ensure the compliance policy allows iOS devices.

Why B: The correct option is B: verify the conditional access policy for Exchange Online includes iOS devices. Since the devices are already enrolled and compliant, the most likely cause is that the conditional access policy is not granting access to Exchange Online for iOS, so the policy must be checked to confirm it targets the iOS platform and the Exchange Online cloud app. Option A is less likely because email settings in a device configuration profile are not required for access when Outlook or the native mail client uses modern authentication. Option C is not the first check because app protection policies govern data handling within apps, not whether Exchange Online access is allowed. Option D is not the issue because the helpdesk already confirmed the devices are compliant.

Variation 2. An organization uses Microsoft Intune to manage devices. They need to ensure that only devices compliant with security baselines can access corporate email via Microsoft Outlook. The solution should use existing Microsoft 365 security features. What should they implement?

medium
  • A.Configure an app protection policy in Microsoft Intune.
  • ✓ B.Create a Conditional Access policy in Microsoft Entra ID that requires compliant device.
  • C.Create a device compliance policy in Microsoft Intune.
  • D.Configure a device configuration profile in Microsoft Intune.

Why B: Conditional Access policies in Microsoft Entra ID evaluate device compliance status before granting access to cloud apps like Exchange Online. By requiring a compliant device, the policy enforces that only devices meeting security baselines can access corporate email via Outlook, leveraging existing Microsoft 365 identity and access management capabilities.

Variation 3. Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. What should you configure?

easy
  • ✓ A.Create a Conditional Access policy that requires compliant device
  • B.Set up enrollment restrictions in Intune
  • C.Create a device configuration policy that blocks non-compliant devices
  • D.Configure an app protection policy for email apps

Why A: A Conditional Access policy in Microsoft Entra ID (formerly Azure AD) can enforce the requirement that only devices marked as compliant by Intune can access corporate email. This policy evaluates the device compliance status at authentication time and blocks or grants access based on that signal, ensuring that only managed and compliant devices can connect to services like Exchange Online.

Variation 4. Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that only compliant devices can access Exchange Online. Which Microsoft Entra ID feature should you use?

easy
  • A.Azure AD device registration
  • ✓ B.Conditional Access with the 'Require device to be marked as compliant' grant
  • C.Multi-factor authentication
  • D.Intune device compliance policy

Why B: Conditional Access policies in Entra ID can require that devices be marked as compliant with Intune compliance policies before granting access to cloud apps like Exchange Online. The other options are not correct: Device Compliance is a policy in Intune, not an Entra feature; MFA is authentication; and Azure AD Join is for device identity.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.