Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Easy

A user reports that they are unable to access a specific internal web application from their personal, non-compliant device. The Conditional Access policy for this application requires devices to be 'compliant' and 'managed'. Which setting in the Conditional Access policy is most likely preventing their access?

  1. AGrant control: Require multi-factor authentication
  2. BDevice state condition
  3. CClient apps condition
  4. DUser risk condition
Show answer & explanation

Correct answer: B. Device state condition

The 'Device state' condition in Conditional Access policies is used to specify whether a device must be Azure AD joined/registered and/or marked as compliant by Intune. A 'non-compliant' device would be blocked by this condition.

Why the other options are wrong

  • A. Requiring MFA is a grant control for identity verification, not a condition for device compliance.
  • C. Client apps condition targets specific applications (e.g., browser, mobile apps), not the device's compliance status.
  • D. User risk assesses the likelihood of a user's identity being compromised, not device compliance.

Conditional Access: Device State

A condition in Conditional Access policies that evaluates whether a device is Azure AD registered/joined and/or compliant with Intune policies, influencing access decisions.

  • Checks device registration/join status.
  • Verifies device compliance from Intune.
  • Critical for 'trusted device' access scenarios.

Memory trick: Device State is the gatekeeper checking your device's health pass.

More Manage identity and compliance (10-15%) questions