SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. Which Microsoft Entra ID feature should you use?
⚠ Common exam trap
It's easy for candidates to confuse Identity Protection (which handles user risk) with device compliance enforcement, but Conditional Access is the only feature that can combine device compliance signals with access control decisions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access
Conditional Access in Microsoft Entra ID is the correct feature because it allows you to enforce policies that require devices to be marked as compliant by Microsoft Intune before granting access to corporate email. By integrating with Intune, Conditional Access evaluates device compliance status in real time and blocks or allows access accordingly, ensuring only managed and compliant devices can reach email resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access
Why this is correct
Microsoft Intune assesses device compliance against organizational policies, such as requiring encryption or specific OS versions. Azure AD Conditional Access then leverages this compliance status as a condition within its policies. This allows organizations to enforce that only devices marked as 'compliant' by Intune are granted access to sensitive cloud applications and data, creating a robust security gate.
- ✗
Privileged Identity Management
Why it's wrong here
Privileged Identity Management (PIM) in Azure AD is designed to manage, control, and monitor access to important resources by providing just-in-time and just-enough access for administrative roles. It helps mitigate the risks associated with excessive, unnecessary, or misused access permissions by requiring activation for privileged roles. PIM's focus is on identity governance for administrators, not on evaluating or enforcing the compliance posture of end-user devices accessing applications.
- ✗
Self-Service Password Reset
Why it's wrong here
Self-Service Password Reset (SSPR) empowers users to securely reset their forgotten or locked passwords without requiring assistance from IT administrators. This feature significantly reduces helpdesk calls and improves user productivity by enabling immediate account recovery. While critical for identity management and user experience, SSPR is solely focused on password lifecycle management and has no functionality related to assessing or enforcing device compliance.
- ✗
Identity Protection
Why it's wrong here
Azure AD Identity Protection is a tool that detects potential vulnerabilities affecting an organization's identities, such as leaked credentials, and identifies suspicious sign-in behaviors like sign-ins from unfamiliar locations or infected devices. It can then automate remediation actions, such as requiring multi-factor authentication or blocking sign-ins, based on detected risks. Its core purpose is to protect user identities from compromise, not to manage or enforce the compliance state of the devices used for access.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.