SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
You are a compliance officer at a healthcare organization that uses Microsoft 365. The organization must comply with HIPAA regulations. You have Microsoft Purview, Microsoft Defender for Cloud Apps, and Microsoft Intune. You need to ensure that all devices accessing patient health information (PHI) are compliant with the organization's security policies, which require device encryption, a minimum OS version, and the use of a compliant mobile device management (MDM) provider. Currently, some devices are not managed by Intune. You need to enforce that only compliant devices can access PHI stored in SharePoint Online. What should you do?
⚠ Common exam trap
SC-900 often tests the boundary between Intune compliance policies (which only classify devices) and Conditional Access (which actually enforces access) — candidates pick the Intune policy thinking it blocks access on its own.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a conditional access policy in Microsoft Entra ID to require compliant devices
Conditional Access in Microsoft Entra ID is the policy engine that evaluates signals such as device compliance state at sign-in time and can grant, block, or require remediation. By creating a CA policy that requires a compliant device (or hybrid Microsoft Entra ID joined device) for the SharePoint Online cloud app, only devices that satisfy the Intune compliance policy (encryption, minimum OS, MDM enrollment) can reach PHI.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a device compliance policy in Microsoft Intune and assign it to all users
Why it's wrong here
Compliance policy alone does not enforce access; conditional access is needed.
- ✗
Deploy an app protection policy in Microsoft Intune to restrict data access
Why it's wrong here
App protection policies apply to apps, not device compliance.
- ✓
Configure a conditional access policy in Microsoft Entra ID to require compliant devices
Why this is correct
A Microsoft Entra ID conditional access policy with the compliant device grant control blocks unmanaged devices from SharePoint Online, enforcing encryption, minimum OS version and MDM enrolment. Intune compliance policies supply the device state that the policy evaluates.
- ✗
Create a DLP policy in Microsoft Purview to block access from non-compliant devices
Why it's wrong here
DLP does not enforce device compliance.
Go deeper
Related to this question
Learn chapter
DLP Policies for Microsoft Teams
Key term
Network Access Control
Network Access Control is a security solution that enforces policies to control which devices and users can connect to a network, ensuring only authorized and compliant endpoints gain access.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.