SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Your organization uses Microsoft Intune and Microsoft Entra ID. You need to enforce that only compliant and managed devices can access corporate email in Microsoft 365. Additionally, if a device is jailbroken, access should be blocked. You also want to provide a seamless sign-in experience for compliant devices. You have Microsoft Entra ID P1 licenses. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy in Microsoft Entra ID that requires device compliance and use Intune compliance policies to block jailbroken devices, with seamless SSO.
It combines Conditional Access policies in Microsoft Entra ID with Intune compliance policies. Conditional Access can require device compliance, and Intune compliance policies can block jailbroken devices. Seamless SSO provides a frictionless sign-in experience for compliant devices. Option A is incorrect because MAM policies manage app-level protection without device enrollment, but they do not enforce device compliance or block jailbroken devices. Option B is incorrect because Azure AD Join registers devices but does not automatically enforce compliance policies or block jailbroken devices. Option D is incorrect because Microsoft Defender for Endpoint is a threat protection solution and does not directly manage device compliance or conditional access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Mobile Application Management (MAM) policies to restrict access.
Why it's wrong here
MAM applies to apps, not device compliance.
- ✗
Configure Azure AD Join for all devices and enable device registration.
Why it's wrong here
Device registration alone does not enforce compliance.
- ✓
Create a Conditional Access policy in Microsoft Entra ID that requires device compliance and use Intune compliance policies to block jailbroken devices, with seamless SSO.
Why this is correct
Conditional Access with device compliance ensures only compliant devices access email.
- ✗
Configure Microsoft Defender for Endpoint to detect jailbroken devices.
Why it's wrong here
Defender for Endpoint does not enforce Conditional Access.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
Defender for Endpoint
Microsoft Defender for Endpoint is a cloud-delivered enterprise security solution designed to protect devices from cyber threats using behavioral analysis, machine learning, and automated investigation.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.