SC-900 Describe the capabilities of Microsoft Entra Practice Question
An organization uses Microsoft Intune to manage devices. They want to ensure that only devices marked as compliant can access corporate email in Exchange Online. Which Conditional Access component should they configure?
⚠ Common exam trap
Test-takers frequently confuse 'Conditions -> Device state' (which filters by platform or state) with the actual compliance enforcement in 'Grant controls', leading candidates to choose Option A thinking it checks compliance directly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant controls -> Require device to be marked as compliant
The 'Require device to be marked as compliant' grant control in Conditional Access enforces that only Intune-compliant devices can access Exchange Online. This integrates with Microsoft Entra ID to check the device compliance status reported by Intune before granting access to corporate email.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conditions -> Device state
Why it's wrong here
The 'Device state' condition in Conditional Access policies identifies whether a device is Azure AD Registered, Azure AD Joined, or Hybrid Azure AD Joined, indicating its enrollment status with Azure AD. While this condition helps target policies to specific types of devices, it merely defines *when* a policy applies, not *what* action is taken to enforce compliance. To actually require a device to be compliant, a 'Grant control' must be configured, as device state alone does not guarantee adherence to security policies.
When this WOULD be correct
This option would be correct if the question were: 'An organization wants to apply a Conditional Access policy only to devices that are not compliant. Which component should they configure?' In that case, 'Conditions -> Device state' would be used to filter for non-compliant devices.
- ✓
Grant controls -> Require device to be marked as compliant
Why this is correct
This Grant control is the precise mechanism within Conditional Access policies to enforce that only devices deemed compliant by a Mobile Device Management (MDM) solution, such as Microsoft Intune, are permitted to access protected resources. By selecting 'Require device to be marked as compliant,' the policy explicitly gates access, ensuring that devices meet organizational security standards before a user can proceed. It directly leverages Intune's compliance reporting to make real-time access decisions.
- ✗
Sign-in risk policy
Why it's wrong here
A sign-in risk policy within Azure Active Directory Identity Protection evaluates the probability that a sign-in attempt is not legitimate, based on various behavioral analytics and threat intelligence, such as impossible travel or sign-ins from infected devices. While crucial for identity security, these policies focus on the risk associated with the user's sign-in activity, not the compliance status or configuration health of the device itself. Therefore, it cannot enforce device compliance as a prerequisite for access.
When this WOULD be correct
A question asks: 'An organization wants to block access to Exchange Online when a sign-in is detected from an anonymous IP address or has leaked credentials. Which Conditional Access component should they configure?' In that scenario, Sign-in risk policy would be correct because it evaluates real-time risk signals during authentication.
- ✗
Session controls -> Use Conditional Access App Control
Why it's wrong here
Session controls, including 'Use Conditional Access App Control,' operate *after* initial access has been granted and are designed to monitor or restrict user actions *during* an active session. These controls, often integrated with Microsoft Defender for Cloud Apps (formerly MCAS), can enforce limitations like blocking downloads or requiring reauthentication within a session. However, they do not function as a pre-access gate to determine if a device meets compliance standards before the session even begins.
When this WOULD be correct
An organization wants to restrict access to a cloud app (e.g., Salesforce) by requiring that sessions be monitored and controlled for data exfiltration, regardless of device compliance. In that scenario, Session controls -> Use Conditional Access App Control would be the correct component.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Grant controls -> Require device to be marked as compliantCorrect answer▾
Why this is correct
This Grant control is the precise mechanism within Conditional Access policies to enforce that only devices deemed compliant by a Mobile Device Management (MDM) solution, such as Microsoft Intune, are permitted to access protected resources. By selecting 'Require device to be marked as compliant,' the policy explicitly gates access, ensuring that devices meet organizational security standards before a user can proceed. It directly leverages Intune's compliance reporting to make real-time access decisions.
✗Conditions -> Device stateWrong answer — click to see why▾
Why this is wrong here
The question asks for the component that enforces access based on device compliance. 'Conditions -> Device state' is a condition that defines which devices are included in the policy, not the control that grants or blocks access. The grant control 'Require device to be marked as compliant' is the actual enforcement mechanism.
★ When this WOULD be the correct answer
This option would be correct if the question were: 'An organization wants to apply a Conditional Access policy only to devices that are not compliant. Which component should they configure?' In that case, 'Conditions -> Device state' would be used to filter for non-compliant devices.
Why candidates choose this
Candidates may confuse the condition (Device state) with the grant control, thinking that setting the condition alone is sufficient to enforce compliance, or they may not fully understand the separation between conditions and grant controls in Conditional Access policies.
✗Sign-in risk policyWrong answer — click to see why▾
Why this is wrong here
Sign-in risk policy is part of Azure AD Identity Protection, not a Conditional Access component. It evaluates the risk level of an authentication attempt, not device compliance, and cannot directly block access based on device compliance status.
★ When this WOULD be the correct answer
A question asks: 'An organization wants to block access to Exchange Online when a sign-in is detected from an anonymous IP address or has leaked credentials. Which Conditional Access component should they configure?' In that scenario, Sign-in risk policy would be correct because it evaluates real-time risk signals during authentication.
Why candidates choose this
Candidates may confuse 'risk' with 'compliance' or think that device compliance is a type of risk condition, leading them to select Sign-in risk policy as a catch-all for security policies.
✗Session controls -> Use Conditional Access App ControlWrong answer — click to see why▾
Why this is wrong here
Session controls with Conditional Access App Control are used to monitor and control app sessions in real time, not to enforce device compliance for email access. The requirement to block non-compliant devices from accessing Exchange Online is achieved via Grant controls, not Session controls.
★ When this WOULD be the correct answer
An organization wants to restrict access to a cloud app (e.g., Salesforce) by requiring that sessions be monitored and controlled for data exfiltration, regardless of device compliance. In that scenario, Session controls -> Use Conditional Access App Control would be the correct component.
Why candidates choose this
Candidates may confuse session-level controls with access enforcement, thinking that controlling the session can enforce compliance, or they may not clearly distinguish between Grant controls and Session controls in Conditional Access policies.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Device compliance
Device compliance is the process of ensuring that a device meets an organization's security and configuration policies before it can access network resources.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.