Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Medium
A company is implementing a Zero Trust security model. They want to ensure that access to highly sensitive applications is only granted from devices that are considered 'trusted'. For Windows 11 devices, this means they must be Azure AD joined and compliant with Intune policies. Which type of Conditional Access grant control should be configured?
- ARequire multi-factor authentication
- BRequire Hybrid Azure AD join
- CRequire device to be marked as compliant
- DRequire approved client app
Show answer & explanationAnswer & explanation
Correct answer: C. Require device to be marked as compliant
The 'Require device to be marked as compliant' grant control in Conditional Access ensures that only devices that meet the organization's compliance policies (as defined in Intune) are granted access, aligning with the 'trusted device' requirement of Zero Trust.
Why the other options are wrong
- A. MFA verifies user identity, not device trustworthiness or compliance.
- B. Requiring Hybrid Azure AD join is a specific device state, but 'compliant' is a broader and more accurate requirement for a 'trusted' device, as a Hybrid Joined device still needs to be compliant.
- D. Requiring an approved client app ensures the app itself is trusted, not the device it runs on.
Conditional Access: Require Compliant Device
A grant control in Conditional Access that mandates a device must be marked as compliant by an MDM solution (like Intune) to gain access to protected resources.
- Enforces device health and security standards.
- Integrates with Intune compliance policies.
- Fundamental for Zero Trust device access.
Memory trick: Grant controls are the 'then' statements, defining what access requires.