Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. What should you configure?

⚠ Common exam trap

Watch out — candidates often confuse a device compliance policy (which only evaluates and marks compliance) with a Conditional Access policy (which enforces the access decision based on that compliance status), leading them to select option A instead of B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A conditional access policy

Conditional Access policies in Azure AD evaluate signals (like device compliance status reported by Intune) to enforce access controls. By configuring a Conditional Access policy that requires device compliance for the Exchange Online or corporate email app, only devices marked as compliant by Intune will be granted access. This is the correct mechanism to gate access based on compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A device compliance policy

    Why it's wrong here

    A device compliance policy defines the security and health standards that a device must meet to be considered 'compliant' within Intune, such as requiring a minimum OS version or disk encryption. While it reports a device's compliance status, this policy type itself does not directly enforce access restrictions to corporate resources. Its primary function is to assess and report, providing the necessary status for other policies to act upon.

  • A conditional access policy

    Why this is correct

    A conditional access policy is the correct mechanism because it acts as the enforcement engine, evaluating various signals including the device's compliance status reported by Intune. This policy can be configured to explicitly require that a device be marked as 'compliant' before granting access to specific cloud applications or services. It effectively bridges device health with access control decisions, ensuring only trusted devices can reach sensitive data.

  • A device configuration policy

    Why it's wrong here

    A device configuration policy is used to deploy specific settings and features to devices, such as Wi-Fi profiles, VPN configurations, or security baselines like password complexity and firewall rules. While these settings contribute to a device's overall security posture, the policy's direct purpose is to configure device behavior and settings, not to define compliance standards or enforce access based on those standards.

  • An app protection policy

    Why it's wrong here

    An app protection policy, also known as Mobile Application Management (MAM), focuses on securing organizational data within specific applications, independent of whether the device itself is managed by Intune. It applies controls like requiring a PIN for app access, preventing data leakage (e.g., copy/paste to personal apps), or encrypting data within the app. This policy type does not assess or enforce device-level compliance or control access to resources based on the device's overall health.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.