SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your company uses Microsoft Entra ID. You need to enforce that all users accessing the HR application must have a device that is compliant with company security policies. The device compliance is managed by Microsoft Intune. Which feature should you use to enforce this requirement?
⚠ Common exam trap
It's easy for candidates to confuse the creation of compliance policies (Intune) with the enforcement of those policies (Conditional Access), assuming that simply defining compliance rules automatically restricts access to applications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Conditional Access
Microsoft Entra Conditional Access is the correct feature because it allows you to create policies that evaluate conditions such as device compliance before granting access to applications. By integrating with Microsoft Intune, Conditional Access can check the device compliance status reported by Intune and block or allow access to the HR application accordingly. This enforces the requirement that only compliant devices can access the app, without requiring users to authenticate differently.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Intune device compliance policies
Why it's wrong here
Microsoft Intune device compliance policies define the security standards and configurations that devices must meet to be considered compliant (e.g., OS version, encryption status, antivirus presence). While these policies are essential for assessing and reporting a device's health, they do not inherently block or grant access to resources. Their enforcement capability relies entirely on integration with Microsoft Entra Conditional Access, which then uses the compliance status as a signal to make access decisions.
- ✓
Microsoft Entra Conditional Access
Why this is correct
Microsoft Entra Conditional Access is the policy engine that evaluates various signals in real-time, such as user identity, location, application, and device state, to make granular access decisions. To enforce device compliance, a Conditional Access policy is configured to require that a device be marked as compliant by an MDM solution like Intune before granting access to protected resources. This directly controls access based on the device's adherence to organizational security standards.
- ✗
Microsoft Entra Multifactor Authentication
Why it's wrong here
Microsoft Entra Multifactor Authentication (MFA) enhances security by requiring users to provide two or more verification methods to prove their identity during sign-in. While MFA is a critical component of a robust security posture, it focuses on verifying *who* the user is, not the security posture or compliance status of the *device* they are using. MFA does not assess or enforce any device-specific health or configuration standards.
- ✗
Microsoft Entra device registration
Why it's wrong here
Microsoft Entra device registration (Entra registered devices) integrates personal or bring-your-own-device (BYOD) devices with Microsoft Entra ID, providing users with single sign-on capabilities to cloud resources and enabling basic device-based Conditional Access. However, device registration itself only establishes an identity for the device within Entra ID and does not inherently assess or enforce any specific compliance standards or security configurations on the device. It is a foundational step but not the mechanism for enforcing compliance.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.