SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company uses Microsoft Entra ID and Intune for mobile device management. They want to enforce different access requirements for their finance application: when users access from an unmanaged personal device, they must perform multi-factor authentication (MFA). When they access from a corporate-managed device that is marked as compliant (e.g., joined to Azure AD, antivirus up-to-date, encryption enabled), MFA should not be required. Device compliance is reported by Intune. Which Microsoft Entra ID feature should they use to define these rules?
⚠ Common exam trap
It's easy for candidates to confuse Intune device compliance policies (which define the rules for compliance) with Conditional Access policies (which enforce access decisions based on that compliance status), leading them to select Option D instead of the correct feature that actually enforces the MFA requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policies
Conditional Access policies in Microsoft Entra ID allow administrators to define granular access rules based on signals such as user, device, location, and application. In this scenario, the policy can be configured to require MFA when the device is not marked as compliant (e.g., unmanaged personal device) and to allow access without MFA when the device is reported as compliant by Intune. This is the correct feature because it directly evaluates device compliance status from Intune and enforces the specified access requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Identity Protection risk policies
Why it's wrong here
Microsoft Entra ID Protection risk policies are designed to detect and respond to potential identity compromises by evaluating user and sign-in risk levels based on anomalous behaviors, leaked credentials, or unfamiliar sign-in properties. While they can enforce MFA or password changes, their focus is solely on user/sign-in risk, not the compliance state of the device itself as managed by Intune. They do not integrate with device compliance signals for access decisions.
When this WOULD be correct
A company wants to block sign-ins from users whose credentials have been leaked or require MFA when sign-in risk is medium or high. Identity Protection risk policies would be the correct feature to define these risk-based access rules.
- ✓
Conditional Access policies
Why this is correct
Conditional Access policies in Microsoft Entra ID are the enforcement engine that evaluates various signals, including device compliance status reported by Intune, user location, and sign-in risk. Based on these conditions, a policy can then enforce specific access controls, such as requiring multi-factor authentication (MFA), blocking access, or requiring a compliant device. This directly addresses the need to control access and enforce MFA based on device state.
- ✗
Privileged Identity Management (PIM)
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) is a service focused on managing, controlling, and monitoring access to important resources within an organization. Its primary function is to provide just-in-time (JIT) and just-enough-access (JEA) for privileged roles, requiring activation and often approval for elevated permissions. PIM does not evaluate device compliance or enforce MFA for general user access to applications based on device health.
When this WOULD be correct
A question asks: 'A company wants to require approval for activating the Global Administrator role and limit its use to a specific time window. Which feature should they use?'
- ✗
Intune device compliance policies
Why it's wrong here
Intune device compliance policies define the security standards and configurations that a device must meet to be considered "compliant" within an organization, such as requiring a PIN, encryption, or specific OS versions. While crucial for establishing device health, these policies themselves do not directly enforce multi-factor authentication or block access to resources. Instead, they report the device's compliance status to Microsoft Entra ID, which Conditional Access policies then utilize for access decisions.
When this WOULD be correct
A company wants to define the specific security requirements (e.g., require encryption, minimum OS version, antivirus) that devices must meet to be considered compliant. The exam question would ask: 'Which feature should they use to set the rules for device compliance?'
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Conditional Access policiesCorrect answer▾
Why this is correct
Conditional Access policies in Microsoft Entra ID are the enforcement engine that evaluates various signals, including device compliance status reported by Intune, user location, and sign-in risk. Based on these conditions, a policy can then enforce specific access controls, such as requiring multi-factor authentication (MFA), blocking access, or requiring a compliant device. This directly addresses the need to control access and enforce MFA based on device state.
✗Identity Protection risk policiesWrong answer — click to see why▾
Why this is wrong here
Identity Protection risk policies focus on user and sign-in risk (e.g., leaked credentials, anonymous IP) to trigger MFA or block access, not on device compliance or management status. The question requires differentiating access based on device compliance (managed vs. unmanaged), which is a Conditional Access condition, not a risk policy.
★ When this WOULD be the correct answer
A company wants to block sign-ins from users whose credentials have been leaked or require MFA when sign-in risk is medium or high. Identity Protection risk policies would be the correct feature to define these risk-based access rules.
Why candidates choose this
Candidates may confuse 'risk' with 'device compliance' because both can trigger MFA, but Identity Protection deals with user/sign-in risk, not device management status.
✗Privileged Identity Management (PIM)Wrong answer — click to see why▾
Why this is wrong here
Privileged Identity Management (PIM) manages just-in-time privileged access and role activation, not access rules based on device compliance or MFA requirements for applications.
★ When this WOULD be the correct answer
A question asks: 'A company wants to require approval for activating the Global Administrator role and limit its use to a specific time window. Which feature should they use?'
Why candidates choose this
Candidates may confuse PIM with Conditional Access because both involve access control, but PIM specifically deals with privileged roles, not general application access policies.
✗Intune device compliance policiesWrong answer — click to see why▾
Why this is wrong here
Intune device compliance policies define the compliance requirements (e.g., antivirus, encryption) but do not enforce access rules like requiring MFA based on device compliance status. Conditional Access policies are needed to combine compliance status with access controls.
★ When this WOULD be the correct answer
A company wants to define the specific security requirements (e.g., require encryption, minimum OS version, antivirus) that devices must meet to be considered compliant. The exam question would ask: 'Which feature should they use to set the rules for device compliance?'
Why candidates choose this
Candidates may confuse device compliance policies (which define compliance) with Conditional Access policies (which enforce access based on compliance). They see 'device compliance' in the scenario and incorrectly assume the policy that defines compliance also enforces the access rules.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Device compliance
Device compliance is the process of ensuring that a device meets an organization's security and configuration policies before it can access network resources.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.