SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that only devices with a TPM (Trusted Platform Module) version 2.0 can access corporate resources. What should you configure?
⚠ Common exam trap
A common mix-up: candidates confuse enrollment restrictions (which only apply at enrollment time) with ongoing compliance enforcement, or they think a configuration profile can block access, when only Conditional Access can enforce the block based on compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a device compliance policy that requires TPM 2.0 and use Conditional Access to block non-compliant devices
A device compliance policy in Microsoft Intune can check for TPM 2.0 presence and version. When combined with a Conditional Access policy that blocks non-compliant devices, only devices meeting the TPM 2.0 requirement can access corporate resources. This is the correct approach because Conditional Access enforces the compliance check at the authentication and authorization layer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a device compliance policy that requires TPM 2.0 and use Conditional Access to block non-compliant devices
Why this is correct
A device compliance policy in Intune can require TPM 2.0 as a compliance rule, and when paired with a Conditional Access policy that requires the device to be marked as compliant, it actively blocks access for non-compliant devices at the time of the resource request. This works as an ongoing access gate, re-evaluating compliance signals on every authentication, so devices missing TPM 2.0 are denied access immediately. That is exactly the intended mechanism for enforcing hardware security baselines on Windows 10 endpoints.
- ✗
Use Windows Update for Business to ensure TPM firmware is updated
Why it's wrong here
Windows Update for Business is a patching and deployment service that controls when security and feature updates are installed, but it has no concept of device compliance status and cannot conditionally block access to corporate resources based on TPM version. Even if a TPM firmware update were delivered, the service does not report compliance to Microsoft Entra ID or integrate with Conditional Access to enforce access decisions. It simply keeps the OS and drivers current; it does not gate access to cloud apps or on-premises resources based on hardware security.
- ✗
Configure device enrollment restrictions to require TPM 2.0
Why it's wrong here
Enrollment restrictions are rules evaluated only at the moment a device attempts to enroll into Intune management, such as blocking devices that fail a TPM or platform check. They are not an ongoing access control mechanism: once a device is enrolled, any later change that drops TPM support or integrity does not trigger any re-evaluation. A device that was compliant at enrollment could still access resources indefinitely without Conditional Access, so this option fails to secure ongoing sessions and data access.
- ✗
Deploy a device configuration profile that enables TPM 2.0
Why it's wrong here
A device configuration profile applies settings and policies to Windows 10 via CSPs, but it cannot actually enable or install a TPM chip—TPM presence and version are determined by hardware and firmware, not by an Intune profile. Even if a profile were used to check or report TPM status, it would not enforce any access requirement or block non-compliant devices on its own. Configuration profiles manage device behavior; they do not integrate with Conditional Access to prohibit access to corporate resources.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.