Courseiva
Describe the capabilities of Microsoft EntrahardMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Your organization uses Microsoft Entra ID and Microsoft Intune. You need to ensure that only managed compliant devices can access corporate email via Outlook mobile app. What is the most efficient approach?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a Conditional Access policy that requires a compliant device and create an app protection policy for Outlook

A Conditional Access policy requiring a compliant device ensures only managed devices can access corporate email, while an app protection policy (APP) adds data protection for the Outlook app, preventing data leakage. Option A is wrong because an app protection policy alone does not enforce device compliance; it only protects data within the app. Option B is wrong because device compliance plus Conditional Access without an app protection policy may allow data leakage from the app. Option C is wrong because MFA only provides authentication, not device management or data protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create an app protection policy in Microsoft Intune for Outlook and assign it to all users

    Why it's wrong here

    An app protection policy (APP) secures corporate data within specific applications by enforcing controls like preventing copy/paste to personal apps or requiring a PIN for app access. However, without a Conditional Access policy requiring a managed or compliant device, any device—including unmanaged personal devices—can still successfully sign in and access the Outlook application. The APP only applies its protections once the user is authenticated and interacting with the app, not at the access gate.

  • Enforce device compliance policies in Intune and create a Conditional Access policy that requires compliant device

    Why it's wrong here

    Enforcing device compliance ensures that only devices meeting organizational security standards, such as having a minimum OS version or encryption enabled, can access corporate resources like Outlook via Conditional Access. While this secures the device's posture, it does not inherently prevent a user from copying sensitive data from the Outlook application to unmanaged personal applications or cloud storage services on that *same compliant device*. A compliant device can still be used to leak data if app-level controls are absent.

  • Create a Conditional Access policy that requires MFA for the Outlook app

    Why it's wrong here

    Multi-Factor Authentication (MFA) significantly enhances security by requiring users to provide two or more verification factors to prove their identity during sign-in. While crucial for preventing unauthorized access through compromised credentials, MFA does not evaluate or enforce the security posture or compliance state of the device being used to access the application. A user could successfully complete MFA from a non-compliant, potentially compromised device, thereby gaining access to Outlook without any device-level security assurances.

  • Create a Conditional Access policy that requires a compliant device and create an app protection policy for Outlook

    Why this is correct

    This combination provides robust security by layering controls. A Conditional Access policy requiring a compliant device ensures that only devices meeting defined security standards can access Outlook, acting as the initial gatekeeper. Concurrently, an app protection policy for Outlook then secures corporate data *within* the application, preventing data leakage by restricting actions like copy/paste to personal apps or saving to unmanaged cloud storage, even on a compliant device. This dual approach protects both the access pathway and the data itself.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.