Courseiva

How to Block Non-Compliant Devices with Conditional Access and Intune

Your organization has deployed Microsoft Intune for mobile device management. You need to ensure that users can only access corporate resources from devices that are compliant with your security policies. Which policy type should you configure?

Quick Answer

The correct answer is a Conditional Access policy. This is because Conditional Access in Microsoft Entra ID acts as the enforcement layer that evaluates device compliance status from Intune before granting access to corporate resources, effectively blocking non-compliant devices. While Intune compliance policies define the security criteria a device must meet, they do not block access on their own; only a Conditional Access policy can use that compliance signal to deny or allow sign-ins. On the SC-900 exam, this question tests your understanding of how Intune and Entra ID work together, with a common trap being to confuse the policy that sets the rules (compliance policy) with the policy that enforces them (Conditional Access). A helpful memory tip is to think of compliance policies as the “what” and Conditional Access as the “when and how”—the compliance policy sets the bar, but Conditional Access is the gatekeeper that checks if the device meets it.

⚠ Common exam trap

Candidates often confuse the role of a compliance policy (which only assesses and reports device status) with a Conditional Access policy (which enforces the access decision based on that status), leading candidates to incorrectly select compliance policy as the enforcement mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A Conditional Access policy

A Conditional Access policy is the correct choice because it enforces access controls at the identity level, evaluating device compliance status before granting access to corporate resources. When combined with Intune compliance policies, Conditional Access can block or allow access based on real-time device health checks, ensuring only compliant devices can connect.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A Conditional Access policy

    Why this is correct

    Conditional Access policies can block or grant access based on device compliance status from Intune.

  • An app protection policy

    Why it's wrong here

    App protection policies manage how data is accessed in apps, not device compliance.

  • A compliance policy

    Why it's wrong here

    Compliance policies define device requirements but need Conditional Access to enforce access control.

  • A configuration policy

    Why it's wrong here

    Configuration policies manage device settings, not access to corporate resources.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization is deploying Microsoft Intune for mobile device management. They need to ensure that all iOS devices must have a passcode of at least 6 characters and the device must be encrypted. What should they configure?

hard
  • A.A Conditional Access policy
  • B.A device configuration profile
  • C.An app protection policy
  • D.A device compliance policy

Why D: Device compliance policies in Intune define the rules that devices must meet to be considered compliant, such as requiring a passcode of at least 6 characters and device encryption. Option A is incorrect because Conditional Access policies use compliance status to enforce access controls, but do not define the compliance rules themselves. Option B is incorrect because device configuration profiles push settings to devices but do not enforce compliance; they are used for configuring device settings. Option C is incorrect because app protection policies manage how apps access and handle data, not device-level requirements like passcode and encryption.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.