SC-900 Describe the capabilities of Microsoft Entra Practice Question
A multinational organization uses Microsoft Entra ID for identity management. The security team wants to implement a Conditional Access policy that blocks access from untrusted locations unless the user's device is marked as compliant by Microsoft Intune. However, users traveling to trusted partner locations should be allowed access even if their device is non-compliant. Which two conditions should be configured in the policy?
⚠ Common exam trap
Many candidates confuse 'exclude trusted locations' with 'include trusted locations,' leading them to choose options that incorrectly apply the policy to trusted locations instead of untrusted ones.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Locations: All locations, exclude trusted locations; Grant: Require compliant device.
The policy must block access from untrusted locations unless the device is compliant, while allowing access from trusted partner locations even if the device is non-compliant. By setting 'Locations: All locations' and excluding trusted locations, the policy applies only to untrusted locations. Then, 'Grant: Require compliant device' ensures that only compliant devices can access from those untrusted locations, meeting both requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Locations: All trusted locations; Grant: Require compliant device.
Why it's wrong here
This policy is configured to apply only to "All trusted locations." Within this limited scope, it mandates that devices must be compliant to gain access to resources. Crucially, this policy does not address access attempts originating from untrusted locations, leaving them unregulated by this specific rule. Therefore, it fails to enforce any compliance requirement for access from untrusted networks, which is a critical security gap.
- ✗
Locations: All trusted locations; Grant: Block access.
Why it's wrong here
This policy is configured to apply to "All trusted locations" and explicitly sets the "Grant" control to "Block access." This configuration would prevent all users, regardless of their device's compliance status, from accessing resources when they are connecting from any location defined as trusted. This outcome is counterproductive, as organizations typically aim to facilitate access from their trusted internal networks rather than blocking it.
- ✓
Locations: All locations, exclude trusted locations; Grant: Require compliant device.
Why this is correct
This policy correctly targets "All locations" while specifically excluding "trusted locations" from its scope. Consequently, it applies only to untrusted network locations. For access attempts originating from these untrusted environments, the policy mandates that the device must be compliant with organizational security standards. Access from trusted locations is not governed by this specific policy, effectively allowing access from those locations without requiring device compliance, which aligns with typical security requirements.
- ✗
Locations: All locations; Grant: Require compliant device.
Why it's wrong here
This policy is configured to apply universally to "All locations," without any exclusions for trusted networks. By setting the "Grant" control to "Require compliant device," this policy would mandate device compliance for access from any network, including those designated as trusted. This approach is overly restrictive, as it would prevent non-compliant devices from accessing resources even when operating within the organization's secure and trusted internal network perimeter.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.