How to Block Non-Compliant Devices with Conditional Access and Intune
Your organization has deployed Microsoft Intune for mobile device management. You need to ensure that users can only access corporate resources from devices that are compliant with your security policies. Which policy type should you configure?
Quick Answer
The correct answer is a Conditional Access policy. This is because Conditional Access in Microsoft Entra ID acts as the enforcement layer that evaluates device compliance status from Intune before granting access to corporate resources, effectively blocking non-compliant devices. While Intune compliance policies define the security criteria a device must meet, they do not block access on their own; only a Conditional Access policy can use that compliance signal to deny or allow sign-ins. On the SC-900 exam, this question tests your understanding of how Intune and Entra ID work together, with a common trap being to confuse the policy that sets the rules (compliance policy) with the policy that enforces them (Conditional Access). A helpful memory tip is to think of compliance policies as the “what” and Conditional Access as the “when and how”—the compliance policy sets the bar, but Conditional Access is the gatekeeper that checks if the device meets it.
⚠ Common exam trap
Candidates often confuse the role of a compliance policy (which only assesses and reports device status) with a Conditional Access policy (which enforces the access decision based on that status), leading candidates to incorrectly select compliance policy as the enforcement mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Conditional Access policy
A Conditional Access policy is the correct choice because it enforces access controls at the identity level, evaluating device compliance status before granting access to corporate resources. When combined with Intune compliance policies, Conditional Access can block or allow access based on real-time device health checks, ensuring only compliant devices can connect.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A Conditional Access policy
Why this is correct
Conditional Access evaluates device compliance state signalled by Intune and grants or blocks access to corporate resources accordingly. This enforces the requirement that only compliant devices connect, which device compliance policies alone cannot do since they merely report state.
- ✗
An app protection policy
Why it's wrong here
App protection policies safeguard corporate data within apps on unmanaged devices, applying encryption and copy-paste restrictions rather than gating resource access on device compliance. They are the right choice when you must protect work data on personal, unenrolled devices that Conditional Access cannot evaluate.
- ✗
A compliance policy
Why it's wrong here
A compliance policy defines the device conditions Intune evaluates, but it does not itself block resource access; that requires a Conditional Access policy in Microsoft Entra ID. Compliance policies are the correct choice when you need to report on and remediate device state, such as marking devices non-compliant after a grace period.
- ✗
A configuration policy
Why it's wrong here
A configuration policy pushes device settings such as Wi-Fi, certificates and restrictions; it does not evaluate device state or gate resource access. It is correct for enforcing settings, whereas conditional access requires a compliance policy marking devices compliant before Microsoft Entra ID grants access.
Go deeper
Related to this question
Learn chapter
Retention Policies and Labels
Key term
Device compliance
Device compliance is the process of ensuring that a device meets an organization's security and configuration policies before it can access network resources.
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization is deploying Microsoft Intune for mobile device management. They need to ensure that all iOS devices must have a passcode of at least 6 characters and the device must be encrypted. What should they configure?
hard- A.A Conditional Access policy
- B.A device configuration profile
- C.An app protection policy
- ✓ D.A device compliance policy
Why D: A device compliance policy in Microsoft Intune defines the security requirements a device must meet (e.g., minimum passcode length, encryption) to be considered compliant. Conditional Access can then require compliant devices for resource access. This is the correct construct for enforcing passcode and encryption settings on iOS devices.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.