Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Easy
A user reports that they are unable to access a specific internal web application from their personal, non-compliant device. The Conditional Access policy for this application requires devices to be 'compliant' and 'managed'. Which setting in the Conditional Access policy is most likely preventing their access?
- AGrant control: Require multi-factor authentication
- BDevice state condition
- CClient apps condition
- DUser risk condition
Show answer & explanationAnswer & explanation
Correct answer: B. Device state condition
The 'Device state' condition in Conditional Access policies is used to specify whether a device must be Azure AD joined/registered and/or marked as compliant by Intune. A 'non-compliant' device would be blocked by this condition.
Why the other options are wrong
- A. Requiring MFA is a grant control for identity verification, not a condition for device compliance.
- C. Client apps condition targets specific applications (e.g., browser, mobile apps), not the device's compliance status.
- D. User risk assesses the likelihood of a user's identity being compromised, not device compliance.
Conditional Access: Device State
A condition in Conditional Access policies that evaluates whether a device is Azure AD registered/joined and/or compliant with Intune policies, influencing access decisions.
- Checks device registration/join status.
- Verifies device compliance from Intune.
- Critical for 'trusted device' access scenarios.
Memory trick: Device State is the gatekeeper checking your device's health pass.