Design solutions that align with security best practices and priorities →mediumMultiple ChoiceObjective-mapped
SC-100 Practice Question: Design solutions that align with security best practices and priorities
Your organization uses Microsoft Intune to manage devices. You need to ensure that devices that are not compliant with your organization's security policies are blocked from accessing corporate resources. Which Intune feature should you configure?
⚠ Common exam trap
Many candidates confuse device configuration profiles (which apply settings) with compliance policies (which evaluate settings and enforce access), leading them to select Option B when the question specifically asks about blocking access based on non-compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compliance policies
Compliance policies in Microsoft Intune define the rules and settings that devices must meet to be considered compliant (e.g., requiring a minimum OS version, encryption, or a healthy device health attestation). When a device is marked as non-compliant, Intune can automatically block access to corporate resources such as Exchange Online, SharePoint, or VPN by integrating with Conditional Access in Microsoft Entra ID. This is the correct feature because it directly evaluates device compliance and enforces access control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
App protection policies
Why it's wrong here
App protection policies in Intune (also known as MAM policies) protect application data by enforcing data-loss prevention measures such as PIN prompts, copy/paste restrictions, and managed clipboard behavior within targeted apps. However, these policies apply only to the application layer and can apply to unmanaged or bring-your-own devices, so they do not produce a device-level compliance evaluation. As a result, they cannot block a device from accessing resources at large; they only control what an end user can do with data inside protected apps. Therefore, they do not serve as the gateway to block access based on device compliance.
- ✗
Device configuration profiles
Why it's wrong here
Device configuration profiles in Microsoft Intune deliver settings to enrolled devices, such as required password length, encryption on, or Wi-Fi/VPN profiles, effectively establishing the intended baseline configuration. But configuration profiles are push-only management constructs; they enforce desired states and do not evaluate or continuously report a device's compliance status for Conditional Access. The compliance status that drives blocking comes from a separate compliance policy object, which assesses the actual state reported by the device. Thus, a configuration profile alone cannot be used to block access for a non-compliant device; it merely attempts to configure the device.
- ✓
Compliance policies
Why this is correct
Compliance policies in Intune define the specific conditions a device must meet to be considered compliant, such as required OS versions, password requirements, encryption status, and threats detected by Mobile Threat Defense. Each device periodically uploads its health and configuration to the Intune service, which computes a compliant/non-compliant state. This state can then be consumed by Azure AD Conditional Access to allow or block access to emails, apps, and data based on real-time compliance. When a policy is combined with a Conditional Access policy requiring device compliance, non-compliant devices are blocked from accessing protected resources—making this the correct answer.
- ✗
Enrollment restrictions
Why it's wrong here
Enrollment restrictions in Intune govern the admission of devices into management by enforcing platform, OS version, and device ownership rules (for example, blocking personal Android or iOS devices or limiting enrollment to corporate-owned devices). These restrictions are evaluated only at enrollment time, when the device first joins Intune, and do not create an ongoing assessment of device compliance. A device can pass enrollment restrictions yet later become non-compliant (e.g., by jailbreaking or disabling encryption), and enrollment restrictions cannot block that device from accessing existing resources. Therefore, while they control the pool of enrolled devices, they do not provide the access-blocking mechanism described in the question.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 208 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.