Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate Microsoft 365 resources. You have configured a Conditional Access policy in Microsoft Entra ID that requires devices to be marked as compliant. However, some users report that they can still access email on their non-compliant Android devices. You need to troubleshoot and resolve the issue. What should you do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Check the Conditional Access policy is enabled and includes 'Office 365 Exchange Online' as a cloud app, and that the users have the appropriate licenses for Intune.

The Conditional Access policy must be enabled and configured to include 'Office 365 Exchange Online' as a cloud app, and the affected users need to have Intune licenses assigned. If the policy is not enabled or does not target the correct app, non-compliant devices may still access email. Option A is incorrect because requiring compliance is the correct setting, not blocking; blocking is a separate action. Option C is incorrect because even if devices are enrolled, the policy must include the correct cloud app and users. Option D is incorrect because while the policy must include users, the primary issue is typically the policy not covering Exchange Online or missing licenses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Change the Conditional Access policy to block access for non-compliant devices instead of requiring compliance.

    Why it's wrong here

    Changing the policy to block instead of require compliance does not address the root cause; the policy may still not be applied correctly.

  • Check the Conditional Access policy is enabled and includes 'Office 365 Exchange Online' as a cloud app, and that the users have the appropriate licenses for Intune.

    Why this is correct

    This is correct: the policy must be enabled, target Exchange Online, and users must have Intune licenses for compliance enforcement.

  • Ensure that the Android devices are enrolled in Microsoft Intune and have a compliance policy assigned.

    Why it's wrong here

    Enrolling devices and assigning compliance policies is necessary, but the issue here is that the Conditional Access policy itself may not be properly configured or scoped.

  • Verify that the Conditional Access policy includes the users who are accessing email.

    Why it's wrong here

    Including the correct users is important, but the primary troubleshooting step is to verify the policy includes the correct cloud app and licensing.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.