Conditional Access to Require Compliant Devices
You are a compliance officer at a healthcare organization that uses Microsoft 365. The organization must comply with HIPAA regulations. You have Microsoft Purview, Microsoft Defender for Cloud Apps, and Microsoft Intune. You need to ensure that all devices accessing patient health information (PHI) are compliant with the organization's security policies, which require device encryption, a minimum OS version, and the use of a compliant mobile device management (MDM) provider. Currently, some devices are not managed by Intune. You need to enforce that only compliant devices can access PHI stored in SharePoint Online. What should you do?
Quick Answer
The answer is to configure a conditional access policy in Microsoft Entra ID to require compliant devices. This is correct because conditional access policies act as the enforcement gatekeeper, checking device compliance—managed by Intune—before granting access to sensitive resources like SharePoint Online containing PHI. While Intune device compliance policies define the rules (encryption, OS version), they cannot block access on their own; conditional access is the mechanism that evaluates those rules and denies non-compliant devices. On the SC-900 exam, this scenario tests your understanding of how Microsoft Entra ID, Intune, and compliance policies work together to enforce zero-trust security, often appearing as a trap where candidates confuse DLP or app protection policies with device-level access control. A common memory tip is: “Intune sets the rules, but Conditional Access enforces the bouncer at the door.”
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a conditional access policy in Microsoft Entra ID to require compliant devices
A conditional access policy in Microsoft Entra ID can be configured to require that devices accessing SharePoint Online be marked as compliant. Device compliance is determined by Intune compliance policies (covering encryption, OS version, MDM enrollment) but the enforcement is done via conditional access. Option A is wrong because creating a compliance policy alone does not enforce the requirement; you need a conditional access policy to block non-compliant devices. Option B is wrong because app protection policies manage data access at the app level but do not enforce device compliance (e.g., OS version or device encryption). Option D is wrong because DLP policies focus on preventing data leakage, not on device compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a device compliance policy in Microsoft Intune and assign it to all users
Why it's wrong here
Compliance policy alone does not enforce access; conditional access is needed.
- ✗
Deploy an app protection policy in Microsoft Intune to restrict data access
Why it's wrong here
App protection policies apply to apps, not device compliance.
- ✓
Configure a conditional access policy in Microsoft Entra ID to require compliant devices
Why this is correct
Conditional access can require devices to be marked as compliant.
- ✗
Create a DLP policy in Microsoft Purview to block access from non-compliant devices
Why it's wrong here
DLP does not enforce device compliance.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Compliance policy
A compliance policy is a set of rules that ensures devices, users, and applications meet an organization's security and regulatory requirements before they can access corporate resources.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization wants to ensure that only managed and compliant devices can access corporate email in Exchange Online. Which Microsoft Entra ID Conditional Access policy setting should they use?
easy- ✓ A.Require device to be marked as compliant
- B.Require approved client app
- C.Require hybrid Azure AD joined device
- D.Require multi-factor authentication
Why A: To ensure only managed and compliant devices access corporate email in Exchange Online, the 'Require device to be marked as compliant' setting in a Conditional Access policy evaluates the device's compliance status reported by Microsoft Intune. This ensures that devices meet security policies (e.g., encryption, patch levels) before granting access, directly addressing the requirement for managed and compliant access.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.