SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company needs to ensure that only approved devices can access corporate resources. Which Microsoft Entra feature should they combine with Microsoft Intune?
⚠ Common exam trap
Test-takers frequently confuse Identity Protection (which deals with user risk) with device-based access control, but Conditional Access is the policy engine that enforces device compliance from Intune.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access
Conditional Access is the Microsoft Entra feature that enforces policies to grant or block access based on conditions such as device compliance. When combined with Microsoft Intune, which manages device compliance policies (e.g., requiring encryption, a specific OS version, or a healthy device health attestation), Conditional Access can block access from non-compliant or unapproved devices. This integration ensures that only devices marked as compliant by Intune can access corporate resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access
Why this is correct
Azure AD Conditional Access policies evaluate conditions such as user, location, application, and device state before granting access to cloud resources. By integrating with Microsoft Intune, Conditional Access can enforce that devices must be marked as compliant with organizational policies (e.g., encryption, OS version, antivirus) before users can access sensitive applications or data. This directly addresses the requirement to ensure only approved devices can access resources.
- ✗
Application Proxy
Why it's wrong here
Azure AD Application Proxy provides secure remote access to on-premises web applications without requiring a VPN. It acts as a reverse proxy, allowing users to access internal resources from anywhere, but its primary function is application publishing and secure connectivity, not evaluating or enforcing the compliance status of the client device itself. It does not have built-in capabilities to assess device approval or compliance.
- ✗
Identity Protection
Why it's wrong here
Azure AD Identity Protection is a tool designed to detect, investigate, and remediate identity-based risks, focusing on user accounts and their sign-in behavior. It identifies compromised credentials, unusual sign-in locations, or other suspicious user activities. While crucial for overall security, Identity Protection does not directly assess or enforce the compliance or approval status of the device being used for access.
- ✗
Privileged Identity Management
Why it's wrong here
Azure AD Privileged Identity Management (PIM) enables organizations to manage, control, and monitor access to important resources by providing just-in-time and just-enough access to privileged roles. It helps mitigate the risks of excessive, unnecessary, or misused access permissions for administrative accounts. PIM's focus is on managing elevated user privileges, not on evaluating or enforcing the security posture or compliance of the devices used by those users.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
Key term
Device compliance
Device compliance is the process of ensuring that a device meets an organization's security and configuration policies before it can access network resources.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.