SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
An organization wants to ensure that only managed and compliant devices can access corporate email in Exchange Online. Which Microsoft Entra ID Conditional Access policy setting should they use?
⚠ Common exam trap
Many candidates confuse 'hybrid Azure AD joined' (a device identity state) with 'compliant' (a device health state), leading them to choose Option C, but only compliance ensures the device meets security policies, not just domain join.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require device to be marked as compliant
To ensure only managed and compliant devices access corporate email in Exchange Online, the 'Require device to be marked as compliant' setting in a Conditional Access policy evaluates the device's compliance status reported by Microsoft Intune. This ensures that devices meet security policies (e.g., encryption, patch levels) before granting access, directly addressing the requirement for managed and compliant access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Require device to be marked as compliant
Why this is correct
This Conditional Access control directly addresses the requirement by ensuring that only devices evaluated and reported as 'compliant' by Microsoft Intune (or a third-party MDM integrated with Azure AD) are granted access. Device compliance policies define security baselines, such as minimum OS versions, encryption status, or antivirus presence. By enforcing this control, the organization guarantees that devices accessing resources adhere to established security standards and are actively managed.
- ✗
Require approved client app
Why it's wrong here
This control specifically targets the application being used, requiring it to be an Intune-managed 'approved client app' that can enforce app protection policies, such as restricting data transfer. While it ensures the app itself is managed and secure, it does not assess or enforce the overall compliance posture or health of the underlying device on which the app is running. Therefore, it fails to meet the requirement for ensuring the *device* is compliant.
- ✗
Require hybrid Azure AD joined device
Why it's wrong here
Requiring a hybrid Azure AD joined device means the device is registered with Azure AD and simultaneously joined to an on-premises Active Directory domain. This establishes a device identity and can be a prerequisite for certain management scenarios. However, being hybrid Azure AD joined does not inherently guarantee that the device is 'compliant' with specific security policies, as its compliance status is determined by separate Intune compliance policies, not merely its join type.
- ✗
Require multi-factor authentication
Why it's wrong here
Multi-factor authentication (MFA) is a critical security measure that strengthens user identity verification by requiring two or more proofs of identity during login. While essential for securing user access, MFA is a user-centric control focused on *who* is accessing, not *what* device they are using. It provides no mechanism to assess, enforce, or report on the security posture or compliance status of the device itself, making it irrelevant for device compliance requirements.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.