Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Medium

A company is implementing a new policy to restrict access to Microsoft 365 services. Users should only be able to access Exchange Online and SharePoint Online from devices that are either compliant or Hybrid Azure AD joined. Access from any other device state should be blocked. Which type of Conditional Access policy condition should you configure to enforce this requirement?

  1. AConditions > Device state
  2. BConditions > Device platforms
  3. CUsers and groups
  4. DCloud apps or actions
Show answer & explanation

Correct answer: A. Conditions > Device state

The 'Device state' condition in Conditional Access policies allows you to specify whether a device must be 'Compliant' or 'Hybrid Azure AD joined' to gain access, directly addressing the requirement to restrict access based on the device's managed status.

Why the other options are wrong

  • B. Device platforms specify the operating system (e.g., Windows, iOS), not whether the device is managed or compliant.
  • C. Users and groups define *who* the policy applies to, not the device's status.
  • D. Cloud apps or actions define *what* resources the policy protects, not the device's state.

Conditional Access Device State Condition

A condition within Conditional Access policies that allows administrators to define access requirements based on the management and compliance status of a device (e.g., Compliant, Hybrid Azure AD joined, Azure AD registered).

  • Crucial for enforcing 'managed device' or 'compliant device' access policies.
  • Leverages Intune's device compliance status.
  • Can be combined with other conditions for granular control.

Memory trick: Conditions define the access gate, by user, app, or device's state.

More Manage identity and compliance (10-15%) questions