SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company uses Microsoft Entra ID. They need to implement a Conditional Access policy for the finance application that requires multifactor authentication (MFA) when a user accesses the app from an unmanaged device. Additionally, they want to block access if the sign-in risk level is high. Which two grant controls should they configure in the policy? (Select two.)
⚠ Common exam trap
It's easy for candidates to confuse 'Require device to be marked as compliant' with 'unmanaged device' conditions, but unmanaged devices are not necessarily non-compliant; the policy specifically targets unmanaged devices for MFA, not compliance enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require multi-factor authentication
The scenario explicitly requires multifactor authentication (MFA) when a user accesses the finance application from an unmanaged device. In Microsoft Entra ID Conditional Access, the 'Require multi-factor authentication' grant control enforces MFA as part of the policy, directly meeting this requirement. Option B is correct because the scenario also requires blocking access if the sign-in risk level is high. The 'Block access' grant control is the appropriate control to deny authentication when a high-risk sign-in is detected, as it overrides any other grant controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Require multi-factor authentication
Why this is correct
This grant control mandates that users successfully complete an additional verification step, such as a phone call, text message, or authenticator app notification, before gaining access to the resource. When applied as a Conditional Access policy, it effectively elevates the authentication strength for specific conditions, like sign-ins from unmanaged devices or high-risk locations. This ensures that even if a primary credential is compromised, unauthorized access is prevented by requiring a second, distinct factor.
- ✓
Block access
Why this is correct
This Conditional Access grant control is the most restrictive, immediately denying any attempt to access the targeted resource or application. It is typically employed for high-risk scenarios, such as when Microsoft Entra ID Protection detects a high sign-in risk, an unfamiliar location, or a compromised credential. Implementing "Block access" ensures that potentially malicious or unauthorized access attempts are completely prevented, safeguarding sensitive data and applications from immediate threats.
- ✗
Require device to be marked as compliant
Why it's wrong here
Incorrect. While this control can enforce device compliance (e.g., Intune), the scenario does not mention a need for device compliance; it only specifies unmanaged device status (which is a condition, not a grant). The requirement is for MFA from unmanaged devices, which is handled by the 'Require MFA' grant.
- ✗
Require approved client app
Why it's wrong here
This grant control specifically restricts access to only those client applications that are explicitly designated as "approved" by the organization, such as Microsoft Outlook or Teams mobile apps with Intune App Protection Policies. It does not address device compliance, sign-in risk, or the need for stronger authentication. Therefore, if the requirement is to enforce MFA from unmanaged devices or block high-risk sign-ins, this control is irrelevant as it focuses solely on the client application's identity and management status.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Conditional Access policy
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.