Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

An organization wants to ensure that only managed and compliant devices can access corporate email in Exchange Online. Which Microsoft Entra ID Conditional Access policy setting should they use?

⚠ Common exam trap

Many candidates confuse 'hybrid Azure AD joined' (a device identity state) with 'compliant' (a device health state), leading them to choose Option C, but only compliance ensures the device meets security policies, not just domain join.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Require device to be marked as compliant

To ensure only managed and compliant devices access corporate email in Exchange Online, the 'Require device to be marked as compliant' setting in a Conditional Access policy evaluates the device's compliance status reported by Microsoft Intune. This ensures that devices meet security policies (e.g., encryption, patch levels) before granting access, directly addressing the requirement for managed and compliant access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Require device to be marked as compliant

    Why this is correct

    This Conditional Access control directly addresses the requirement by ensuring that only devices evaluated and reported as 'compliant' by Microsoft Intune (or a third-party MDM integrated with Azure AD) are granted access. Device compliance policies define security baselines, such as minimum OS versions, encryption status, or antivirus presence. By enforcing this control, the organization guarantees that devices accessing resources adhere to established security standards and are actively managed.

  • Require approved client app

    Why it's wrong here

    This control specifically targets the application being used, requiring it to be an Intune-managed 'approved client app' that can enforce app protection policies, such as restricting data transfer. While it ensures the app itself is managed and secure, it does not assess or enforce the overall compliance posture or health of the underlying device on which the app is running. Therefore, it fails to meet the requirement for ensuring the *device* is compliant.

  • Require hybrid Azure AD joined device

    Why it's wrong here

    Requiring a hybrid Azure AD joined device means the device is registered with Azure AD and simultaneously joined to an on-premises Active Directory domain. This establishes a device identity and can be a prerequisite for certain management scenarios. However, being hybrid Azure AD joined does not inherently guarantee that the device is 'compliant' with specific security policies, as its compliance status is determined by separate Intune compliance policies, not merely its join type.

  • Require multi-factor authentication

    Why it's wrong here

    Multi-factor authentication (MFA) is a critical security measure that strengthens user identity verification by requiring two or more proofs of identity during login. While essential for securing user access, MFA is a user-centric control focused on *who* is accessing, not *what* device they are using. It provides no mechanism to assess, enforce, or report on the security posture or compliance status of the device itself, making it irrelevant for device compliance requirements.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.