Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Hard
A global company needs to ensure that all user devices accessing corporate resources are registered with Azure Active Directory (Azure AD) and are compliant with company policies. This includes personal mobile devices (BYOD) and corporate laptops. Which Azure AD device state fully satisfies both requirements?
- AHybrid Azure AD joined
- BAzure AD registered and Intune compliant
- CAzure AD registered
- DAzure AD joined
Show answer & explanationAnswer & explanation
Correct answer: B. Azure AD registered and Intune compliant
To ensure devices are registered and compliant, they must first be registered (Azure AD Registered for BYOD, or Joined/Hybrid Joined for corporate) and then explicitly marked as 'compliant' by a management solution like Intune. 'Azure AD registered and Intune compliant' covers both conditions for all device types.
Why the other options are wrong
- A. Hybrid Azure AD joined indicates domain-joined and registered, but doesn't explicitly guarantee compliance without an MDM.
- C. Azure AD registered only indicates registration, not compliance with policies.
- D. Azure AD joined indicates corporate ownership and management, but doesn't explicitly guarantee compliance without an MDM.
Azure AD Device States and Compliance
Azure AD device states (Registered, Joined, Hybrid Joined) define how a device connects to Azure AD, while Intune compliance status indicates if it meets organizational policies.
- Registered: BYOD, provides SSO.
- Joined/Hybrid Joined: Corporate, full management.
- Compliance requires MDM (e.g., Intune) evaluation.
Memory trick: Registered is good, compliant is golden, together they unlock access.