Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

An organization uses Microsoft Intune to manage devices. They want to ensure that only devices that are compliant with security policies (e.g., encryption enabled, latest patches) can access corporate email. Which Microsoft Entra feature should they use to enforce this requirement?

⚠ Common exam trap

SC-900 often tests the confusion between Intune compliance policies (which define/report compliance) and Conditional Access (which enforces access based on that compliance) — candidates pick Intune because it 'sounds like' the enforcement point.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access in Microsoft Entra ID

Conditional Access in Microsoft Entra ID is the policy engine that evaluates signals (user, device, location, app) and enforces access decisions such as requiring a compliant device before granting access to corporate email. It specifically integrates with Intune's device compliance status via the 'Require device to be marked as compliant' grant control, blocking non-compliant devices from Exchange Online and other cloud apps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conditional Access in Microsoft Entra ID

    Why this is correct

    Conditional Access evaluates signals such as device compliance state from Microsoft Intune and enforces grant controls, so only compliant, encrypted, patched devices reach Exchange Online. This satisfies the requirement to block non-compliant devices from corporate email at authentication time.

  • ✗

    Microsoft Defender for Endpoint

    Why it's wrong here

    Microsoft Defender for Endpoint detects and remediates threats on endpoints, yet it does not decide whether a device may authenticate to Exchange Online. It is the right choice for attack detection, investigation and response, but the requirement to admit only compliant devices to email is enforced by Conditional Access, not by endpoint detection signals alone.

  • ✗

    Device compliance policies in Microsoft Intune

    Why it's wrong here

    Device compliance policies evaluate encryption and patch state and mark devices compliant or not, but they do not themselves gate access to email; a Conditional Access policy must consume that signal. Compliance policies are the right choice for defining and reporting the security baseline, while enforcement of the access requirement needs Conditional Access.

  • ✗

    Microsoft Entra ID Join

    Why it's wrong here

    Microsoft Entra ID Join registers a device with Microsoft Entra ID and enables single sign-on, but it does not evaluate encryption or patch levels, so an unpatched device still authenticates. Joining is correct when you need cloud-based device identity and management enrolment, whereas blocking non-compliant devices from email requires a Conditional Access policy acting on compliance state.

Go deeper

Related to this question

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.