SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email via the Outlook mobile app. Which policy type should you configure?
⚠ Common exam trap
Many candidates confuse device compliance policies (which only define and report compliance) with Conditional Access policies (which enforce access decisions based on that compliance), leading them to incorrectly select Option C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policies in Microsoft Entra ID
Conditional Access policies in Microsoft Entra ID are the correct choice because they evaluate device compliance status (reported by Intune) as a condition for granting access to cloud apps like Exchange Online. By requiring that only compliant devices can access corporate email via the Outlook mobile app, you configure a Conditional Access policy that blocks or grants access based on the device compliance state, integrating Intune's compliance assessment with Entra ID's access control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Device configuration policies
Why it's wrong here
Device configuration policies in Microsoft Intune are primarily used to deploy specific settings, features, and security controls directly to managed devices. Examples include configuring Wi-Fi profiles, VPN connections, email accounts, or enforcing device restrictions like disabling cameras or requiring passcodes. While essential for establishing a secure device baseline, they define how a device operates and is secured, but do not directly evaluate a device's compliance status to grant or deny access to cloud applications.
- ✗
App protection policies
Why it's wrong here
App protection policies, also known as Mobile Application Management (MAM) policies, focus on protecting organizational data within specific applications, independent of whether the device itself is managed by Intune. They enforce data loss prevention (DLP) controls such as restricting copy/paste, preventing "save as" to personal storage, or requiring a PIN to access the app. App protection policies safeguard data at the application layer and do not assess or require device compliance for access to cloud services.
- ✗
Device compliance policies
Why it's wrong here
Device compliance policies in Microsoft Intune define the security posture requirements that a device must meet to be considered "compliant" (e.g., minimum OS version, encryption status, antivirus presence). While they report a device's compliance status to Microsoft Entra ID, they do not inherently block or grant access to resources on their own. Their function is to assess device health; an additional mechanism is required to act upon that compliance status to control resource access.
- ✓
Conditional Access policies in Microsoft Entra ID
Why this is correct
Conditional Access policies in Microsoft Entra ID serve as the enforcement engine that evaluates various signals, including the device compliance status reported by Intune, to make real-time access decisions for cloud applications. Conditional Access policies can be configured to explicitly require a device to be marked as "compliant" by Intune before allowing access to sensitive organizational resources, thereby linking device health directly to identity-based access control. They are the critical component for enforcing device compliance for cloud app access.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Compliance state
Compliance state is the current status of a system, application, or device indicating whether it meets a defined set of security policies, regulatory requirements, or configuration standards.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.