SC-900 Describe the capabilities of Microsoft Entra Practice Question
A user reports they cannot access the company portal from their personal device. The device is not enrolled in Microsoft Intune. The admin wants to ensure only compliant devices can access corporate resources. What should the admin configure?
⚠ Common exam trap
A common mix-up: candidates confuse device compliance policies with sign-in risk policies or identity governance features, mistakenly thinking risk-based controls or PIM can enforce device health, when only Conditional Access with Intune compliance can block non-enrolled personal devices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policy requiring device compliance
A is correct because a Conditional Access policy can require device compliance before granting access to corporate resources. When the device is not enrolled in Microsoft Intune, it cannot report compliance status, so the policy blocks access. This ensures only managed, compliant devices can access the company portal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access policy requiring device compliance
Why this is correct
Conditional Access policies evaluate specific conditions, such as device state, before granting access to cloud applications like the company portal. By requiring a device to be marked as compliant by Microsoft Intune, these policies ensure that only devices meeting organizational security standards (e.g., OS version, encryption, antivirus) can access sensitive resources. This directly addresses a user's inability to access the portal if their device fails compliance checks, making it the correct solution.
- ✗
Enable password writeback
Why it's wrong here
Password writeback is a feature of Microsoft Entra Connect that allows password changes made in Microsoft Entra ID to be synchronized back to an on-premises Active Directory domain. Its primary function is to enable users to reset or change their cloud passwords and have those changes reflected on-premises. This capability has no bearing on a device's ability to access the company portal based on its compliance status or any other access policy.
- ✗
Enable Identity Protection sign-in risk policy
Why it's wrong here
Microsoft Entra Identity Protection sign-in risk policies detect and respond to potential threats during the sign-in process, such as sign-ins from unfamiliar locations or infected devices. While it can block or challenge risky sign-ins, its focus is on user identity risk and the security of the sign-in itself, not the device's adherence to organizational compliance standards like patch levels or encryption. Therefore, it would not directly resolve an issue related to device compliance blocking access.
- ✗
Microsoft Entra Privileged Identity Management
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) is a service designed to manage, control, and monitor access to important resources within an organization by providing just-in-time and just-enough access to privileged roles. It focuses on elevating user permissions for administrative tasks, not on enforcing device compliance or granting general access to applications like a company portal for regular users. PIM is unrelated to a user's device access issue based on compliance.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.