Courseiva

Conditional Access to Require Compliant Devices

You are a compliance officer at a healthcare organization that uses Microsoft 365. The organization must comply with HIPAA regulations. You have Microsoft Purview, Microsoft Defender for Cloud Apps, and Microsoft Intune. You need to ensure that all devices accessing patient health information (PHI) are compliant with the organization's security policies, which require device encryption, a minimum OS version, and the use of a compliant mobile device management (MDM) provider. Currently, some devices are not managed by Intune. You need to enforce that only compliant devices can access PHI stored in SharePoint Online. What should you do?

Quick Answer

The answer is to configure a conditional access policy in Microsoft Entra ID to require compliant devices. This is correct because conditional access policies act as the enforcement gatekeeper, checking device compliance—managed by Intune—before granting access to sensitive resources like SharePoint Online containing PHI. While Intune device compliance policies define the rules (encryption, OS version), they cannot block access on their own; conditional access is the mechanism that evaluates those rules and denies non-compliant devices. On the SC-900 exam, this scenario tests your understanding of how Microsoft Entra ID, Intune, and compliance policies work together to enforce zero-trust security, often appearing as a trap where candidates confuse DLP or app protection policies with device-level access control. A common memory tip is: “Intune sets the rules, but Conditional Access enforces the bouncer at the door.”

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure a conditional access policy in Microsoft Entra ID to require compliant devices

A conditional access policy in Microsoft Entra ID can be configured to require that devices accessing SharePoint Online be marked as compliant. Device compliance is determined by Intune compliance policies (covering encryption, OS version, MDM enrollment) but the enforcement is done via conditional access. Option A is wrong because creating a compliance policy alone does not enforce the requirement; you need a conditional access policy to block non-compliant devices. Option B is wrong because app protection policies manage data access at the app level but do not enforce device compliance (e.g., OS version or device encryption). Option D is wrong because DLP policies focus on preventing data leakage, not on device compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a device compliance policy in Microsoft Intune and assign it to all users

    Why it's wrong here

    Compliance policy alone does not enforce access; conditional access is needed.

  • Deploy an app protection policy in Microsoft Intune to restrict data access

    Why it's wrong here

    App protection policies apply to apps, not device compliance.

  • Configure a conditional access policy in Microsoft Entra ID to require compliant devices

    Why this is correct

    Conditional access can require devices to be marked as compliant.

  • Create a DLP policy in Microsoft Purview to block access from non-compliant devices

    Why it's wrong here

    DLP does not enforce device compliance.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization wants to ensure that only managed and compliant devices can access corporate email in Exchange Online. Which Microsoft Entra ID Conditional Access policy setting should they use?

easy
  • A.Require device to be marked as compliant
  • B.Require approved client app
  • C.Require hybrid Azure AD joined device
  • D.Require multi-factor authentication

Why A: To ensure only managed and compliant devices access corporate email in Exchange Online, the 'Require device to be marked as compliant' setting in a Conditional Access policy evaluates the device's compliance status reported by Microsoft Intune. This ensures that devices meet security policies (e.g., encryption, patch levels) before granting access, directly addressing the requirement for managed and compliant access.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.