Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Medium

A user reports that they cannot access a specific SharePoint Online site from their personal laptop, which is not enrolled in Intune. The error message indicates that their device does not meet the organization's compliance requirements. You have already verified that the user's account is enabled and has the correct permissions to the SharePoint site. Which policy type is most likely preventing access?

  1. AApp protection policy
  2. BDevice compliance policy
  3. CDevice configuration profile
  4. DConditional Access policy
Show answer & explanation

Correct answer: D. Conditional Access policy

Conditional Access policies are used to enforce access restrictions based on various conditions, including device state (e.g., 'compliant' or 'hybrid Azure AD joined'). An unmanaged personal laptop would likely fail a Conditional Access policy requiring a compliant device.

Why the other options are wrong

  • A. App protection policies focus on data protection *within* apps once access is granted, not on blocking access at the authentication stage.
  • B. Device compliance policies apply to devices *managed* by Intune. The laptop is not enrolled.
  • C. Device configuration profiles apply settings to *managed* devices. The laptop is not enrolled.

Conditional Access

A feature of Azure Active Directory that enables organizations to enforce policies for accessing resources based on specific conditions, such as user location, device state, application, and sign-in risk.

  • Acts as a gatekeeper for resource access.
  • Can require multi-factor authentication, compliant devices, or trusted locations.
  • Integrates with Intune for device compliance checks.

Memory trick: Conditional Access: Only if conditions are right, the door opens with all its might.

More Manage identity and compliance (10-15%) questions