Courseiva
Describe the capabilities of Microsoft EntramediumMultiple SelectObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

A company uses Microsoft Entra ID. They need to implement a Conditional Access policy for the finance application that requires multifactor authentication (MFA) when a user accesses the app from an unmanaged device. Additionally, they want to block access if the sign-in risk level is high. Which two grant controls should they configure in the policy? (Select two.)

⚠ Common exam trap

It's easy for candidates to confuse 'Require device to be marked as compliant' with 'unmanaged device' conditions, but unmanaged devices are not necessarily non-compliant; the policy specifically targets unmanaged devices for MFA, not compliance enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Require multi-factor authentication

The scenario explicitly requires multifactor authentication (MFA) when a user accesses the finance application from an unmanaged device. In Microsoft Entra ID Conditional Access, the 'Require multi-factor authentication' grant control enforces MFA as part of the policy, directly meeting this requirement. Option B is correct because the scenario also requires blocking access if the sign-in risk level is high. The 'Block access' grant control is the appropriate control to deny authentication when a high-risk sign-in is detected, as it overrides any other grant controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Require multi-factor authentication

    Why this is correct

    This grant control mandates that users successfully complete an additional verification step, such as a phone call, text message, or authenticator app notification, before gaining access to the resource. When applied as a Conditional Access policy, it effectively elevates the authentication strength for specific conditions, like sign-ins from unmanaged devices or high-risk locations. This ensures that even if a primary credential is compromised, unauthorized access is prevented by requiring a second, distinct factor.

  • Block access

    Why this is correct

    This Conditional Access grant control is the most restrictive, immediately denying any attempt to access the targeted resource or application. It is typically employed for high-risk scenarios, such as when Microsoft Entra ID Protection detects a high sign-in risk, an unfamiliar location, or a compromised credential. Implementing "Block access" ensures that potentially malicious or unauthorized access attempts are completely prevented, safeguarding sensitive data and applications from immediate threats.

  • Require device to be marked as compliant

    Why it's wrong here

    Incorrect. While this control can enforce device compliance (e.g., Intune), the scenario does not mention a need for device compliance; it only specifies unmanaged device status (which is a condition, not a grant). The requirement is for MFA from unmanaged devices, which is handled by the 'Require MFA' grant.

  • Require approved client app

    Why it's wrong here

    This grant control specifically restricts access to only those client applications that are explicitly designated as "approved" by the organization, such as Microsoft Outlook or Teams mobile apps with Intune App Protection Policies. It does not address device compliance, sign-in risk, or the need for stronger authentication. Therefore, if the requirement is to enforce MFA from unmanaged devices or block high-risk sign-ins, this control is irrelevant as it focuses solely on the client application's identity and management status.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.