Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

Your organization uses Microsoft Intune and Microsoft Entra ID. You need to enforce that only compliant and managed devices can access corporate email in Microsoft 365. Additionally, if a device is jailbroken, access should be blocked. You also want to provide a seamless sign-in experience for compliant devices. You have Microsoft Entra ID P1 licenses. What should you configure?

⚠ Common exam trap

SC-900 often tests the confusion between MAM (app-level protection) and Conditional Access with device compliance (device-level access control), leading candidates to choose MAM when device compliance and jailbreak blocking are required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Conditional Access policy in Microsoft Entra ID that requires device compliance and use Intune compliance policies to block jailbroken devices, with seamless SSO.

To enforce that only compliant and managed devices access corporate email, and to block jailbroken devices, the correct approach is a Conditional Access policy in Microsoft Entra ID that requires device compliance, combined with Intune compliance policies that detect and block jailbroken devices. Enabling seamless SSO provides the desired sign-in experience for compliant devices. This combination satisfies all stated requirements with Entra ID P1 licensing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure Mobile Application Management (MAM) policies to restrict access.

    Why it's wrong here

    MAM policies govern app-level data handling on unmanaged devices, so they cannot require device compliance or block jailbroken hardware from Microsoft 365 email. It tempts for BYOD scenarios protecting corporate data within apps, but conditional access with device compliance and Intune jailbreak detection is needed here.

  • ✗

    Configure Microsoft Entra ID Join for all devices and enable device registration.

    Why it's wrong here

    Microsoft Entra ID Join registers devices into Microsoft Entra ID but enforces no compliance or jailbreak condition; access control requires Conditional Access with Intune compliance policies. Hybrid or Entra join is tempting when the goal is centralised device identity and single sign-on, but it supplies identity, not device health gating.

  • ✓

    Create a Conditional Access policy in Microsoft Entra ID that requires device compliance and use Intune compliance policies to block jailbroken devices, with seamless SSO.

    Why this is correct

    Conditional Access enforces the compliance requirement at authentication time, granting or denying access based on Intune device state, so jailbroken devices flagged non-compliant are blocked. Intune compliance policies supply that device signal, while Microsoft Entra join with seamless SSO satisfies the seamless sign-in constraint. Entra ID P1 licences cover Conditional Access.

  • ✗

    Configure Microsoft Defender for Endpoint to detect jailbroken devices.

    Why it's wrong here

    Defender for Endpoint detects jailbroken devices and raises alerts, yet detection alone does not block Microsoft 365 email access; enforcement needs Conditional Access grant controls tied to Intune compliance. It is tempting because Defender genuinely identifies compromised devices, which suits threat investigation rather than access authorisation.

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.