A company uses Microsoft Entra ID. They want to enforce that users accessing the payroll application from outside the corporate network must use multifactor authentication and must access the app only from devices that are marked as compliant by Intune. Which Conditional Access component should they use to combine these requirements?
Grant controls are the 'then' part of a Microsoft Entra Conditional Access policy that dictate what must be satisfied *before* access to a cloud application is granted. These controls allow administrators to enforce specific requirements such as requiring multi-factor authentication (MFA), a device marked as compliant, or a hybrid Azure AD joined device. They directly enforce the desired authentication and device posture necessary for access.
Why this answer
B is correct because Grant controls in a Conditional Access policy allow administrators to specify the access requirements that must be satisfied before a user can access a resource. In this scenario, the requirement to enforce both multifactor authentication and device compliance (from Intune) is achieved by configuring the Grant control to 'Require multifactor authentication' and 'Require device to be marked as compliant', combined with the 'Require all the selected controls' option. This ensures that both conditions must be met simultaneously for access to the payroll application from outside the corporate network.
Exam trap
The trap here is that candidates confuse 'Conditions' (the 'when' and 'where' of the policy) with 'Grant controls' (the 'what must happen' to gain access), leading them to incorrectly select Conditions as the component that combines the requirements.
How to eliminate wrong answers
Option A is wrong because Conditions define the signals or triggers for the policy (e.g., user location, device platform, application), not the actions or requirements that must be met once the policy is triggered. Option C is wrong because Sign-in risk policy is a specific type of Identity Protection policy that responds to real-time risk detections (e.g., anonymous IP address, atypical travel) and is not designed to combine static requirements like MFA and device compliance for a specific application. Option D is wrong because Session controls enforce limitations on the user session after access is granted (e.g., app-enforced restrictions, sign-in frequency), not the pre-access requirements like MFA or device compliance.