Your organization is using Microsoft Entra ID and has deployed Microsoft Intune for mobile device management. You need to ensure that only devices that are compliant with Intune policies can access corporate email via Microsoft Outlook for iOS and Android. Additionally, you need to prevent users from copying corporate data to personal apps on the same device. Which two Microsoft Entra features should you combine?
A Conditional Access policy requiring a compliant device ensures that only devices meeting specific security baselines, as defined and monitored by Microsoft Intune, can access corporate resources. This enforces device health and configuration, ensuring the device adheres to organizational security standards. Microsoft Intune App Protection Policies (MAM) provide a crucial layer of data protection within applications, preventing corporate data from being copied, pasted, or saved to unmanaged applications or personal storage locations, even on unmanaged devices. Together, these policies establish both device-level security posture and application-level data leakage prevention, directly addressing the need to protect data and enforce compliance.
Why this answer
Option D is correct because it combines the two features that directly address both requirements: a Conditional Access policy with the 'Require device to be marked as compliant' grant control ensures only Intune-compliant devices can access Exchange Online from Outlook mobile, while an Intune app protection policy (MAM) applied to Outlook enforces data-sharing restrictions such as blocking copy/paste to unmanaged personal apps. These work together via app-based Conditional Access, where the compliant-device requirement gates access and the MAM policy governs how corporate data can be used within the app. Option A is wrong because hybrid Azure AD join and Windows Autopilot target Windows device provisioning, not iOS/Android Outlook access or app-level data controls.
Option B is wrong because MFA and Windows Hello for Business address authentication strength on Windows, not device compliance or data leakage prevention. Option C is wrong because Azure AD Application Proxy publishes on-premises web apps and does not prevent copy/paste of corporate data in mobile apps.