mediumMultiple Select
Zero Trust Identity: Intune, Azure AD Registration, and Conditional Access for Device Compliance
A company is implementing a Zero Trust identity strategy. They want to ensure that only compliant and managed devices can access corporate resources. Which THREE components should they include in their solution? (Choose three.)
Quick Answer
The answer is Azure AD Conditional Access policies, Microsoft Intune, and Azure AD device registration. These three components work together to enforce a Zero Trust identity strategy by ensuring only compliant and managed devices can access corporate resources. Intune defines the compliance policies—such as requiring encryption, a minimum OS version, or specific patch levels—while Azure AD device registration establishes a device’s identity and management status. Conditional Access policies then evaluate both the device’s compliance and registration state during authentication, blocking or granting access accordingly. On the Microsoft Cybersecurity Architect exam, this scenario tests your understanding of how device compliance integrates with identity-driven access control, often appearing as a multi-select question where a common trap is to include a standalone tool like Microsoft Defender for Endpoint instead of the core identity-device triad. Remember the mnemonic “ICR” for Intune, Conditional Access, and Registration—if any piece is missing, the Zero Trust identity loop is broken.
⚠ Common exam trap
A common mix-up: candidates confuse Microsoft Entra application proxy (a publishing tool) with a device compliance mechanism, or assume Microsoft Entra B2B collaboration can enforce device management for external users, when in fact neither component evaluates device health or management status.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Intune for device management and compliance policies
Microsoft Intune (A) is the correct MDM/MAM service for enforcing device compliance policies (e.g., encryption, OS version, jailbreak detection) and marking devices as managed or compliant, which is the foundation for device-based Zero Trust access. Microsoft Entra ID device registration (B) is required so devices have an identity in Microsoft Entra ID (registered, joined, or hybrid-joined), enabling Conditional Access to evaluate device state and compliance signals. Microsoft Entra Conditional Access policies (C) are the policy engine that enforces the requirement that only compliant and managed devices can access corporate resources, using conditions and grant controls tied to device compliance. Microsoft Entra application proxy (D) is a remote-access/publishing solution for on-premises web apps and does not enforce device compliance or management. Microsoft Entra B2B collaboration (E) governs external guest user access and is unrelated to ensuring devices are managed and compliant.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Intune for device management and compliance policies
Why this is correct
Microsoft Intune enforces device compliance and management state, which Microsoft Entra ID then evaluates through Conditional Access before granting resource access. This directly satisfies the stem's requirement that only compliant, managed devices connect, supplying the device signal Zero Trust needs for policy enforcement.
- ✓
Microsoft Entra ID device registration
Why this is correct
Device registration creates the identity record in Microsoft Entra ID that links a physical device to the tenant, enabling Conditional Access to recognise and evaluate it. It establishes the device object required before compliance or join state can be assessed.
- ✓
Microsoft Entra Conditional Access policies
Why this is correct
Conditional Access is the policy engine that grants or blocks resource access based on device compliance and management state, directly enforcing the Zero Trust requirement. It evaluates signals from Intune and device registration at authentication time.
- ✗
Microsoft Entra application proxy
Why it's wrong here
Microsoft Entra application proxy publishes internal web apps for remote users; it does not evaluate device compliance or management state, so it cannot enforce the conditional access requirement. It is tempting because it is an identity-related access component, but device compliance needs Microsoft Entra ID conditional access with Intune-managed device signals.
- ✗
Microsoft Entra B2B collaboration
Why it's wrong here
B2B collaboration governs external partner identities, not device compliance or management state. It is tempting because it extends access to guest users, which is the correct choice when the requirement is federating with suppliers or partners rather than enforcing managed, compliant device conditions.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization is implementing a Zero Trust identity strategy. They have a mix of on-premises Active Directory and Azure AD. They want to enforce conditional access policies that require device compliance for accessing sensitive apps. However, some users report that their devices are not being evaluated for compliance even though they are enrolled in Microsoft Intune. What should the organization check first?
hard- A.Ensure Intune compliance policies are assigned to the correct user groups
- B.Confirm that devices are Azure AD Joined
- C.Check if users have enabled multi-factor authentication
- ✓ D.Verify that devices are registered in Azure AD
Why D: Device compliance evaluation in a hybrid identity environment requires that devices are registered in Azure AD (Azure AD Registration) so that Azure AD can associate the device identity with Intune compliance data. Even if a device is enrolled in Intune, without Azure AD registration, Conditional Access policies cannot evaluate its compliance status because the device identity is not recognized by Azure AD during authentication.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.