Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Your company uses Microsoft Intune to manage devices. You need to ensure that only devices that are compliant with your security policies can access corporate email via Microsoft Outlook. What should you implement?

⚠ Common exam trap

A common mix-up: candidates confuse device compliance policies (which only define and report compliance) with Conditional Access (which enforces access decisions based on that compliance state), leading them to select Option B instead of D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conditional Access policies

Conditional Access policies (D) are the correct choice because they evaluate device compliance status—determined by Intune compliance policies—as a condition for granting access. By configuring a Conditional Access policy that requires compliant devices, only devices meeting your security policies can authenticate to Microsoft Outlook and access corporate email. This is the Azure AD/Entra ID mechanism that enforces access control based on compliance state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Windows Information Protection

    Why it's wrong here

    Windows Information Protection (WIP) is a data loss prevention (DLP) feature designed to protect enterprise data on Windows devices by separating corporate and personal data. It prevents accidental data leakage by restricting actions like copying corporate data to personal applications or saving it to unauthorized locations. However, WIP operates at the data handling layer on the device and does not control initial access to cloud services like email based on device compliance.

  • Device compliance policies

    Why it's wrong here

    Device compliance policies in Microsoft Intune define the security standards and configurations that devices must meet to be considered compliant, such as requiring a passcode, encryption, or a specific operating system version. While these policies assess and report a device's compliance status to Azure Active Directory, they do not directly enforce access restrictions to applications or services themselves. Their primary function is to establish and report the health posture of a device, acting as a prerequisite for access control.

  • App protection policies

    Why it's wrong here

    App protection policies, also known as Mobile Application Management (MAM) policies, secure organizational data within specific applications, even on devices not fully managed by Intune. These policies enforce data protection settings like requiring a PIN for app access, encrypting app data, or preventing data transfer between corporate and personal applications. Critically, app protection policies do not evaluate the overall compliance status of the device to grant or deny initial access to cloud services like email.

  • Conditional Access policies

    Why this is correct

    Conditional Access policies in Azure Active Directory are the robust control plane for enforcing access decisions to cloud applications, including email, based on various signals. These policies evaluate conditions such as user identity, location, application, and crucially, the device's compliance status as reported by Intune. Based on this evaluation, Conditional Access can grant access, block access, or require additional authentication methods, making it the definitive mechanism for enforcing access control based on device compliance.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.