SC-900 Describe the capabilities of Microsoft Entra Practice Question
Exhibit
{
"device": {
"deviceId": "device123",
"operatingSystem": "Windows 10",
"trustType": "Microsoft Entra ID joined",
"isCompliant": true,
"isManaged": true,
"profileType": "Workplace"
}
}Refer to the exhibit. You are configuring a Conditional Access policy that requires compliant device for access to Microsoft 365. The device shown in the exhibit is Microsoft Entra ID joined, compliant, and managed. However, a user signing in from this device is still blocked. What is the most likely cause?
⚠ Common exam trap
Many candidates assume 'compliant' and 'managed' automatically satisfy all Conditional Access device requirements, but Microsoft distinguishes between Microsoft Entra ID joined, Hybrid Microsoft Entra ID joined, and registered devices, and policies can require a specific join type that the device does not meet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Conditional Access policy requires Hybrid Microsoft Entra ID joined device.
The exhibit shows the device is Microsoft Entra ID joined, compliant, and managed, yet the user is still blocked. This indicates the Conditional Access policy is configured to require a Hybrid Microsoft Entra ID joined device, which is a stricter requirement than just being Microsoft Entra ID joined. A Hybrid Microsoft Entra ID joined device must be both domain-joined to on-premises Active Directory and registered with Microsoft Entra ID, whereas an Microsoft Entra ID joined device is only cloud-joined. Since the device in the exhibit is only Microsoft Entra ID joined, it does not satisfy the Hybrid Microsoft Entra ID joined condition, causing the block.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The device profile type is 'Workplace', which is not allowed.
Why it's wrong here
The term 'Workplace' as a device profile type is not a standard classification that would inherently block access in Conditional Access. Microsoft Entra ID joined devices, which might be colloquially referred to as 'workplace' devices, are a fully supported device state for Conditional Access policies. If the device is correctly Microsoft Entra ID joined and meets other policy requirements, this profile type itself would not be a reason for access denial.
- ✗
The device is not compliant.
Why it's wrong here
The exhibit explicitly indicates that the device's 'isCompliant' status is 'true'. Conditional Access policies often require devices to be marked as compliant by a Mobile Device Management (MDM) solution like Microsoft Intune. Since the device has successfully reported its compliance status as true, this specific condition for access has been met, and therefore, non-compliance is not the reason for the access block.
- ✗
The device is not managed.
Why it's wrong here
The exhibit clearly states that the device's 'isManaged' status is 'true'. A managed device typically means it is enrolled in an MDM solution, such as Microsoft Intune, or is Microsoft Entra ID joined/Hybrid Microsoft Entra ID joined. Since the device is indeed managed, this condition, if required by the Conditional Access policy, has been satisfied, eliminating 'not managed' as the cause for access denial.
- ✓
The Conditional Access policy requires Hybrid Microsoft Entra ID joined device.
Why this is correct
The exhibit implies the device is Microsoft Entra ID joined, which is distinct from a Hybrid Microsoft Entra ID joined device. A Hybrid Microsoft Entra ID joined device is registered with both on-premises Active Directory and Microsoft Entra ID. If the Conditional Access policy is specifically configured to grant access only to Hybrid Microsoft Entra ID joined devices, an Microsoft Entra ID joined-only device would fail this requirement, leading to access being blocked. This mismatch in device join type is a common reason for Conditional Access policy enforcement.
Go deeper
Related to this question
Learn chapter
Session and Access Policies in Defender for Cloud Apps
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Conditional Access policy
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.