Courseiva
Describe the capabilities of Microsoft EntrahardMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

A company uses Microsoft Entra ID and Intune for mobile device management. They want to enforce different access requirements for their finance application: when users access from an unmanaged personal device, they must perform multi-factor authentication (MFA). When they access from a corporate-managed device that is marked as compliant (e.g., joined to Azure AD, antivirus up-to-date, encryption enabled), MFA should not be required. Device compliance is reported by Intune. Which Microsoft Entra ID feature should they use to define these rules?

⚠ Common exam trap

It's easy for candidates to confuse Intune device compliance policies (which define the rules for compliance) with Conditional Access policies (which enforce access decisions based on that compliance status), leading them to select Option D instead of the correct feature that actually enforces the MFA requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conditional Access policies

Conditional Access policies in Microsoft Entra ID allow administrators to define granular access rules based on signals such as user, device, location, and application. In this scenario, the policy can be configured to require MFA when the device is not marked as compliant (e.g., unmanaged personal device) and to allow access without MFA when the device is reported as compliant by Intune. This is the correct feature because it directly evaluates device compliance status from Intune and enforces the specified access requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Identity Protection risk policies

    Why it's wrong here

    Microsoft Entra ID Protection risk policies are designed to detect and respond to potential identity compromises by evaluating user and sign-in risk levels based on anomalous behaviors, leaked credentials, or unfamiliar sign-in properties. While they can enforce MFA or password changes, their focus is solely on user/sign-in risk, not the compliance state of the device itself as managed by Intune. They do not integrate with device compliance signals for access decisions.

    When this WOULD be correct

    A company wants to block sign-ins from users whose credentials have been leaked or require MFA when sign-in risk is medium or high. Identity Protection risk policies would be the correct feature to define these risk-based access rules.

  • Conditional Access policies

    Why this is correct

    Conditional Access policies in Microsoft Entra ID are the enforcement engine that evaluates various signals, including device compliance status reported by Intune, user location, and sign-in risk. Based on these conditions, a policy can then enforce specific access controls, such as requiring multi-factor authentication (MFA), blocking access, or requiring a compliant device. This directly addresses the need to control access and enforce MFA based on device state.

  • Privileged Identity Management (PIM)

    Why it's wrong here

    Microsoft Entra Privileged Identity Management (PIM) is a service focused on managing, controlling, and monitoring access to important resources within an organization. Its primary function is to provide just-in-time (JIT) and just-enough-access (JEA) for privileged roles, requiring activation and often approval for elevated permissions. PIM does not evaluate device compliance or enforce MFA for general user access to applications based on device health.

    When this WOULD be correct

    A question asks: 'A company wants to require approval for activating the Global Administrator role and limit its use to a specific time window. Which feature should they use?'

  • Intune device compliance policies

    Why it's wrong here

    Intune device compliance policies define the security standards and configurations that a device must meet to be considered "compliant" within an organization, such as requiring a PIN, encryption, or specific OS versions. While crucial for establishing device health, these policies themselves do not directly enforce multi-factor authentication or block access to resources. Instead, they report the device's compliance status to Microsoft Entra ID, which Conditional Access policies then utilize for access decisions.

    When this WOULD be correct

    A company wants to define the specific security requirements (e.g., require encryption, minimum OS version, antivirus) that devices must meet to be considered compliant. The exam question would ask: 'Which feature should they use to set the rules for device compliance?'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Conditional Access policiesCorrect answer

Why this is correct

Conditional Access policies in Microsoft Entra ID are the enforcement engine that evaluates various signals, including device compliance status reported by Intune, user location, and sign-in risk. Based on these conditions, a policy can then enforce specific access controls, such as requiring multi-factor authentication (MFA), blocking access, or requiring a compliant device. This directly addresses the need to control access and enforce MFA based on device state.

Identity Protection risk policiesWrong answer — click to see why

Why this is wrong here

Identity Protection risk policies focus on user and sign-in risk (e.g., leaked credentials, anonymous IP) to trigger MFA or block access, not on device compliance or management status. The question requires differentiating access based on device compliance (managed vs. unmanaged), which is a Conditional Access condition, not a risk policy.

★ When this WOULD be the correct answer

A company wants to block sign-ins from users whose credentials have been leaked or require MFA when sign-in risk is medium or high. Identity Protection risk policies would be the correct feature to define these risk-based access rules.

Why candidates choose this

Candidates may confuse 'risk' with 'device compliance' because both can trigger MFA, but Identity Protection deals with user/sign-in risk, not device management status.

Privileged Identity Management (PIM)Wrong answer — click to see why

Why this is wrong here

Privileged Identity Management (PIM) manages just-in-time privileged access and role activation, not access rules based on device compliance or MFA requirements for applications.

★ When this WOULD be the correct answer

A question asks: 'A company wants to require approval for activating the Global Administrator role and limit its use to a specific time window. Which feature should they use?'

Why candidates choose this

Candidates may confuse PIM with Conditional Access because both involve access control, but PIM specifically deals with privileged roles, not general application access policies.

Intune device compliance policiesWrong answer — click to see why

Why this is wrong here

Intune device compliance policies define the compliance requirements (e.g., antivirus, encryption) but do not enforce access rules like requiring MFA based on device compliance status. Conditional Access policies are needed to combine compliance status with access controls.

★ When this WOULD be the correct answer

A company wants to define the specific security requirements (e.g., require encryption, minimum OS version, antivirus) that devices must meet to be considered compliant. The exam question would ask: 'Which feature should they use to set the rules for device compliance?'

Why candidates choose this

Candidates may confuse device compliance policies (which define compliance) with Conditional Access policies (which enforce access based on compliance). They see 'device compliance' in the scenario and incorrectly assume the policy that defines compliance also enforces the access rules.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.