SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company uses Microsoft Entra ID. They have a financial application that should only be accessible from Windows devices. The security team wants to create a Conditional Access policy to block access from other operating systems such as macOS or Linux. Which assignment condition should they configure?
⚠ Common exam trap
Test-takers frequently confuse Device platforms with Client apps, thinking that blocking 'mobile apps' or 'browsers' would restrict the OS, but Client apps only controls the type of application client, not the underlying operating system.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Device platforms
The Device platforms condition in a Conditional Access policy allows administrators to target specific operating systems (e.g., Windows, iOS, Android, macOS) or block others. By configuring this condition to only include Windows devices, the policy will block access from macOS, Linux, or any other non-Windows platform. This directly addresses the security team's requirement to restrict the financial application to Windows devices only.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Locations
Why it's wrong here
The Locations condition in Microsoft Entra Conditional Access is designed to enforce policies based on the network origin of the access request. It allows administrators to define trusted IP ranges, specific countries/regions, or exclude known locations, thereby controlling access based on where the user is connecting from. This condition does not, however, inspect or evaluate the operating system of the device making the connection, rendering it unsuitable for enforcing restrictions based on device platforms like Windows or macOS.
When this WOULD be correct
A Conditional Access policy should block access from untrusted countries or corporate network ranges. For example, 'Block access from all locations except the corporate office IP range' would use the Locations condition.
- ✓
Device platforms
Why this is correct
The Device platforms condition in Microsoft Entra Conditional Access precisely targets the operating system of the device attempting to access resources. By configuring this condition to include only specific OS types, such as Windows, administrators can effectively block access attempts originating from non-compliant or unauthorized platforms like macOS, iOS, Android, or Linux. This ensures that sensitive financial data is only accessed from devices running approved operating systems, directly meeting the requirement to restrict access based on the device's OS.
- ✗
Client apps
Why it's wrong here
The Client apps condition specifies which types of client applications can access the protected resource, such as web browsers, mobile apps, or desktop clients. This condition allows for granular control over how users connect to services, for instance, by blocking access from legacy authentication clients or requiring modern authentication. However, it focuses on the application type initiating the request, not the underlying operating system running that application, making it ineffective for enforcing policies based on the device's platform.
When this WOULD be correct
A Conditional Access policy should block access from specific client apps, such as blocking legacy authentication protocols (e.g., POP, IMAP) to enforce modern authentication. For example, a policy that blocks all client apps except 'Exchange ActiveSync' to secure email access.
- ✗
Sign-in risk
Why it's wrong here
The Sign-in risk condition evaluates the likelihood that a sign-in attempt is not performed by the legitimate user, leveraging real-time and historical data from Microsoft Entra ID Protection. While crucial for detecting suspicious activities like impossible travel or unfamiliar sign-in properties, this condition focuses on the risk associated with the sign-in event itself, not the underlying operating system of the device being used. Therefore, it cannot be used to specifically restrict access based on whether the device is running Windows, macOS, or another platform.
When this WOULD be correct
A Conditional Access policy should block access when the sign-in risk level is 'High' to prevent compromised accounts from accessing sensitive data, such as requiring MFA or blocking access entirely for high-risk sign-ins.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Device platformsCorrect answer▾
Why this is correct
The Device platforms condition in Microsoft Entra Conditional Access precisely targets the operating system of the device attempting to access resources. By configuring this condition to include only specific OS types, such as Windows, administrators can effectively block access attempts originating from non-compliant or unauthorized platforms like macOS, iOS, Android, or Linux. This ensures that sensitive financial data is only accessed from devices running approved operating systems, directly meeting the requirement to restrict access based on the device's OS.
✗LocationsWrong answer — click to see why▾
Why this is wrong here
Locations control access based on geographic or network locations (e.g., IP ranges), not the operating system of the device. The requirement is to block macOS and Linux, which is about device platform, not location.
★ When this WOULD be the correct answer
A Conditional Access policy should block access from untrusted countries or corporate network ranges. For example, 'Block access from all locations except the corporate office IP range' would use the Locations condition.
Why candidates choose this
Candidates may confuse 'location' with 'device' or think that restricting by location can indirectly control device types, but Azure AD locations are IP-based, not OS-based.
✗Client appsWrong answer — click to see why▾
Why this is wrong here
The question specifies blocking access based on the operating system (Windows vs. macOS/Linux), which is a device platform condition, not a client app condition. Client apps refer to the type of application (e.g., browser, mobile app, legacy auth), not the OS.
★ When this WOULD be the correct answer
A Conditional Access policy should block access from specific client apps, such as blocking legacy authentication protocols (e.g., POP, IMAP) to enforce modern authentication. For example, a policy that blocks all client apps except 'Exchange ActiveSync' to secure email access.
Why candidates choose this
Candidates may confuse 'client apps' with 'device platforms' because both involve the endpoint, but client apps focus on the application type (e.g., browser, mobile app) rather than the operating system.
✗Sign-in riskWrong answer — click to see why▾
Why this is wrong here
Sign-in risk is used to detect and respond to risky authentication attempts (e.g., leaked credentials, anonymous IP addresses), not to restrict access based on the device's operating system. The question specifically requires blocking macOS or Linux, which is a device platform condition.
★ When this WOULD be the correct answer
A Conditional Access policy should block access when the sign-in risk level is 'High' to prevent compromised accounts from accessing sensitive data, such as requiring MFA or blocking access entirely for high-risk sign-ins.
Why candidates choose this
Candidates may confuse risk-based controls with device-based controls, thinking that blocking non-Windows devices is a security measure similar to blocking risky sign-ins, but they address different aspects of access control.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.