Design security operations, identity, and compliance capabilities →hardMultiple ChoiceObjective-mapped
SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Intune to manage devices and wants to ensure that only compliant devices can access corporate email. Which conditional access policy setting should you configure?
⚠ Common exam trap
A common mix-up: candidates confuse 'Require approved client app' (which controls app-level access) with device compliance, thinking that restricting the app is sufficient to secure email, but it does not enforce device health or configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require device to be marked as compliant
The 'Require device to be marked as compliant' setting in a Conditional Access policy enforces that only devices meeting your Intune compliance policies (e.g., encryption, OS version, threat level) can access corporate email. This setting checks the device's compliance status reported by Intune to Azure AD during authentication, blocking non-compliant devices before they reach Exchange Online.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Require device to be marked as compliant
Why this is correct
The 'Require device to be marked as compliant' grant control is correct because Intune compliance policies evaluate the device's configuration, health, and security posture. In Conditional Access, this control blocks access unless the device meets the specific compliance criteria defined in Intune, such as encryption, patch level, and threat detection. It ensures a device-level trust boundary before granting access to corporate resources, making it the appropriate device compliance control.
- ✗
Require approved client app
Why it's wrong here
'Require approved client app' is incorrect because it enforces an application-level protection policy, not device compliance. This control verifies that the user's app (e.g., Outlook) is managed by an Intune app protection policy and is approved, but it does not evaluate the underlying device's health, configuration, or compliance status. Thus, it cannot serve as a substitute for the device compliance requirement.
- ✗
Require Multi-Factor Authentication
Why it's wrong here
'Require Multi-Factor Authentication' is incorrect because MFA validates the user's identity through an additional authentication factor, unrelated to the device's compliance. Device compliance is a separate condition that checks the physical and logical state of the device, such as jailbreak, operating system version, or device threat level. MFA and device compliance are complementary controls, but MFA alone does not enforce device compliance.
- ✗
Require domain join
Why it's wrong here
'Require domain join' is incorrect because domain join (hybrid Azure AD join) indicates membership in an on-premises Active Directory domain, not compliance with Intune policies. A domain-joined device could still be non-compliant if it lacks security updates, has misconfigured settings, or fails health attestation. Intune compliance is based on device configuration and health, not solely on domain membership.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.