Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Your organization wants to prevent users from installing unapproved apps on company-managed Windows devices. Which Microsoft Intune feature should you use?

⚠ Common exam trap

Watch out — candidates often confuse device compliance policies (which check device state) with app control policies (which enforce runtime app execution), leading them to choose compliance policies when the question specifically asks about preventing app installation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

App control policies

App control policies in Microsoft Intune allow administrators to create and enforce rules that control which applications users can run on managed Windows devices. By configuring a baseline policy (e.g., using Windows Defender Application Control), you can block unapproved apps while allowing only trusted or explicitly permitted software, directly preventing users from installing unauthorized applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • App control policies

    Why this is correct

    App control policies, such as Windows Defender Application Control (WDAC) or AppLocker, are specifically designed to restrict which applications can run on devices. These policies enforce a strict allowlist or blocklist, preventing the execution of unauthorized software, including user-installed applications. By defining trusted applications based on publisher, path, or hash, they directly address the requirement to block unapproved installations and executions, ensuring a secure software environment.

  • Device configuration profiles

    Why it's wrong here

    Device configuration profiles in Microsoft Intune are primarily used to manage various settings and features on devices, such as Wi-Fi profiles, VPN connections, email settings, and general security configurations. While they can enforce certain system-level restrictions, they do not inherently provide the granular control necessary to block the installation or execution of specific unapproved applications. Their purpose is to standardize device settings, not to act as an application allowlisting or blocklisting mechanism.

  • Conditional Access

    Why it's wrong here

    Conditional Access policies in Azure AD are identity-driven controls that determine whether a user can access specific cloud applications or resources based on various conditions like user location, device state, or sign-in risk. These policies enforce requirements such as multi-factor authentication or compliant devices before granting access. However, Conditional Access does not directly prevent users from installing unauthorized applications onto their local devices; its scope is focused on controlling access to protected resources, not managing local device software execution.

  • Device compliance policies

    Why it's wrong here

    Device compliance policies define the security standards and health requirements that devices must meet to be considered compliant within an organization. These policies assess attributes like OS version, encryption status, or antivirus presence. While a non-compliant device might be blocked from accessing corporate resources via Conditional Access, compliance policies themselves do not actively prevent users from installing unapproved applications. They report on a device's state rather than enforcing application execution control.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.