SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company uses Microsoft Entra ID. The security team wants to allow users to sign in only from devices that are known and managed by the organization, and to block sign-ins from personal devices. They need to enforce this for all users accessing Microsoft 365 apps. What should they configure?
⚠ Common exam trap
Watch out — candidates often confuse device-based Conditional Access with risk-based ID Protection policies, which assess compromise likelihood rather than device ownership.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Conditional Access policy that requires the device to be marked as compliant or Microsoft Entra hybrid joined.
Conditional Access is the policy engine in Microsoft Entra ID that evaluates signals such as user, device, location, and app to make access decisions. Requiring the device to be compliant or Microsoft Entra hybrid joined ensures that only devices managed by the organization are granted access. This directly satisfies the need to block personal devices while allowing corporate-managed devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A Conditional Access policy that requires the device to be marked as compliant or Microsoft Entra hybrid joined.
Why this is correct
Conditional Access can evaluate device state as a condition. By requiring the device to be compliant or Microsoft Entra hybrid joined, only organizational devices allowed by Intune or joined to on-premises AD are permitted. This directly enforces the requirement to block personal devices for Microsoft 365 apps.
- ✗
Multi-factor authentication (MFA) registration for all users, enforced through Security Defaults.
Why it's wrong here
MFA strengthens authentication by requiring additional verification, but it does not check device compliance or join state. Personal devices could still access Microsoft 365 apps after MFA. Security Defaults apply a baseline set of policies but do not include device-based conditions, so they cannot block personal devices.
- ✗
A named location in Microsoft Entra ID that includes only the corporate network IP ranges, and a Conditional Access policy that blocks all other locations.
Why it's wrong here
Named locations restrict access based on network location, not device ownership. Users on personal devices connected to the corporate network would still be allowed, and managed devices outside the network would be blocked. This does not meet the requirement to allow only known organizational devices regardless of location.
- ✗
A Microsoft Entra ID Protection risk policy that blocks sign-ins with a high sign-in risk.
Why it's wrong here
ID Protection risk policies evaluate the likelihood that a sign-in or user is compromised, not whether the device is corporate-owned. They cannot distinguish personal from managed devices. Therefore, they would not enforce the device-based access requirement described, and personal devices could still sign in if no risk is detected.
Go deeper
Related to this question
Learn chapter
Session and Access Policies in Defender for Cloud Apps
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.