SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization wants to prevent users from installing unapproved apps on company-managed Windows devices. Which Microsoft Intune feature should you use?
⚠ Common exam trap
Watch out — candidates often confuse device compliance policies (which check device state) with app control policies (which enforce runtime app execution), leading them to choose compliance policies when the question specifically asks about preventing app installation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
App control policies
App control policies in Microsoft Intune allow administrators to create and enforce rules that control which applications users can run on managed Windows devices. By configuring a baseline policy (e.g., using Windows Defender Application Control), you can block unapproved apps while allowing only trusted or explicitly permitted software, directly preventing users from installing unauthorized applications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
App control policies
Why this is correct
App control policies, such as Windows Defender Application Control (WDAC) or AppLocker, are specifically designed to restrict which applications can run on devices. These policies enforce a strict allowlist or blocklist, preventing the execution of unauthorized software, including user-installed applications. By defining trusted applications based on publisher, path, or hash, they directly address the requirement to block unapproved installations and executions, ensuring a secure software environment.
- ✗
Device configuration profiles
Why it's wrong here
Device configuration profiles in Microsoft Intune are primarily used to manage various settings and features on devices, such as Wi-Fi profiles, VPN connections, email settings, and general security configurations. While they can enforce certain system-level restrictions, they do not inherently provide the granular control necessary to block the installation or execution of specific unapproved applications. Their purpose is to standardize device settings, not to act as an application allowlisting or blocklisting mechanism.
- ✗
Conditional Access
Why it's wrong here
Conditional Access policies in Azure AD are identity-driven controls that determine whether a user can access specific cloud applications or resources based on various conditions like user location, device state, or sign-in risk. These policies enforce requirements such as multi-factor authentication or compliant devices before granting access. However, Conditional Access does not directly prevent users from installing unauthorized applications onto their local devices; its scope is focused on controlling access to protected resources, not managing local device software execution.
- ✗
Device compliance policies
Why it's wrong here
Device compliance policies define the security standards and health requirements that devices must meet to be considered compliant within an organization. These policies assess attributes like OS version, encryption status, or antivirus presence. While a non-compliant device might be blocked from accessing corporate resources via Conditional Access, compliance policies themselves do not actively prevent users from installing unapproved applications. They report on a device's state rather than enforcing application execution control.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Baseline
A baseline is a documented starting point for the normal performance and behavior of a system, network, or component, used to detect changes and troubleshoot issues.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.