Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantMedium

A Microsoft 365 administrator is setting up a new tenant and needs to ensure that users can only access Microsoft 365 resources from trusted devices. They also want to prevent users from downloading sensitive company data to unmanaged devices. Which feature should the administrator implement?

  1. AMicrosoft Intune device compliance policies
  2. BAzure AD Identity Protection
  3. CMicrosoft Defender for Cloud Apps (MDCA) file policies
  4. DAzure AD Conditional Access with session controls
Show answer & explanation

Correct answer: D. Azure AD Conditional Access with session controls

Azure AD Conditional Access, combined with session controls, allows administrators to define policies that restrict access to resources based on device state (trusted/unmanaged) and can enforce actions like blocking downloads to unmanaged devices.

Why the other options are wrong

  • A. Intune device compliance policies assess device health but don't directly control access to M365 resources or block downloads in the context of a session.
  • B. Identity Protection detects and remediates identity risks, not device trust or data download restrictions.
  • C. MDCA file policies are for governing existing files, not for preventing initial downloads based on device trust during a session.

Conditional Access Session Controls

Azure AD Conditional Access policies that apply controls during a user's session, enabling actions like blocking downloads, requiring compliant devices, or using a less restrictive experience.

  • Enforces policies after initial authentication.
  • Integrates with Microsoft Defender for Cloud Apps (MDCA) for advanced controls.
  • Can restrict actions like download, print, or copy on unmanaged devices.

Memory trick: Conditional Access is the bouncer for your digital club.

More Deploy and manage a Microsoft 365 tenant questions