Courseiva
Describe the capabilities of Microsoft EntraeasyMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Your organization wants to allow employees to use their personal mobile devices to access corporate resources, but you need to ensure that corporate data is protected if the device is lost or stolen. You also need to enforce a PIN policy on the device. Which combination of Microsoft Entra and Microsoft Intune features should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enroll devices in Microsoft Intune MDM, create a device compliance policy requiring PIN, and configure a Conditional Access policy to allow only compliant devices.

Enrolling devices in Microsoft Intune MDM allows the organization to apply device compliance policies (such as requiring a PIN) and then use Conditional Access to grant access only to compliant devices. If a device is lost or stolen, the organization can perform a selective wipe to remove corporate data while leaving personal data intact. Option A (Windows Autopilot) is a device provisioning tool, not a security or protection solution. Option B (Conditional Access with MFA and trusted locations) does not enforce device-level policies like PIN. Option D (MAM without enrollment) can enforce a PIN for managed apps but cannot manage the device itself or perform selective wipe of all corporate data; it is less comprehensive than MDM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use Windows Autopilot to configure devices and then apply a device restriction policy.

    Why it's wrong here

    Incorrect: Autopilot is for Windows devices only and does not address loss/theft scenario.

  • Implement a Conditional Access policy requiring multi-factor authentication and trusted locations.

    Why it's wrong here

    Incorrect: This does not enforce PIN or allow wipe.

  • Enroll devices in Microsoft Intune MDM, create a device compliance policy requiring PIN, and configure a Conditional Access policy to allow only compliant devices.

    Why this is correct

    Correct: MDM enrollment enables compliance policies and remote wipe of corporate data.

  • Use Microsoft Intune app protection policies (MAM) without device enrollment, requiring PIN for managed apps.

    Why it's wrong here

    Incorrect: MAM does not allow selective wipe of all corporate data on the device, only app-level wipe.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.