SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your organization uses Microsoft Entra ID and Microsoft Intune. You need to ensure that only managed compliant devices can access corporate email via Outlook mobile app. What is the most efficient approach?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy that requires a compliant device and create an app protection policy for Outlook
A Conditional Access policy requiring a compliant device ensures only managed devices can access corporate email, while an app protection policy (APP) adds data protection for the Outlook app, preventing data leakage. Option A is wrong because an app protection policy alone does not enforce device compliance; it only protects data within the app. Option B is wrong because device compliance plus Conditional Access without an app protection policy may allow data leakage from the app. Option C is wrong because MFA only provides authentication, not device management or data protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an app protection policy in Microsoft Intune for Outlook and assign it to all users
Why it's wrong here
An app protection policy (APP) secures corporate data within specific applications by enforcing controls like preventing copy/paste to personal apps or requiring a PIN for app access. However, without a Conditional Access policy requiring a managed or compliant device, any device—including unmanaged personal devices—can still successfully sign in and access the Outlook application. The APP only applies its protections once the user is authenticated and interacting with the app, not at the access gate.
- ✗
Enforce device compliance policies in Intune and create a Conditional Access policy that requires compliant device
Why it's wrong here
Enforcing device compliance ensures that only devices meeting organizational security standards, such as having a minimum OS version or encryption enabled, can access corporate resources like Outlook via Conditional Access. While this secures the device's posture, it does not inherently prevent a user from copying sensitive data from the Outlook application to unmanaged personal applications or cloud storage services on that *same compliant device*. A compliant device can still be used to leak data if app-level controls are absent.
- ✗
Create a Conditional Access policy that requires MFA for the Outlook app
Why it's wrong here
Multi-Factor Authentication (MFA) significantly enhances security by requiring users to provide two or more verification factors to prove their identity during sign-in. While crucial for preventing unauthorized access through compromised credentials, MFA does not evaluate or enforce the security posture or compliance state of the device being used to access the application. A user could successfully complete MFA from a non-compliant, potentially compromised device, thereby gaining access to Outlook without any device-level security assurances.
- ✓
Create a Conditional Access policy that requires a compliant device and create an app protection policy for Outlook
Why this is correct
This combination provides robust security by layering controls. A Conditional Access policy requiring a compliant device ensures that only devices meeting defined security standards can access Outlook, acting as the initial gatekeeper. Concurrently, an app protection policy for Outlook then secures corporate data *within* the application, preventing data leakage by restricting actions like copy/paste to personal apps or saving to unmanaged cloud storage, even on a compliant device. This dual approach protects both the access pathway and the data itself.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
App protection policy
An app protection policy is a set of rules that controls how data is handled and secured within mobile applications, ensuring corporate information stays safe even on personal devices.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.