Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsMedium

A global enterprise uses Microsoft 365 for its productivity suite and has a hybrid cloud environment with resources in Azure and on-premises. The security team needs a unified solution to manage device compliance, deploy applications, and enforce security policies across all corporate-owned and personal devices, regardless of their location. Which Microsoft security solution best meets these requirements?

  1. AMicrosoft Intune
  2. BAzure Active Directory Identity Protection
  3. CMicrosoft Defender for Endpoint
  4. DMicrosoft Defender for Cloud Apps
Show answer & explanation

Correct answer: A. Microsoft Intune

Microsoft Intune is a cloud-based service that focuses on mobile device management (MDM) and mobile application management (MAM), allowing organizations to control how devices are used and manage corporate data on those devices, including compliance and policy enforcement.

Why the other options are wrong

  • B. Azure Active Directory Identity Protection focuses on detecting and remediating identity-based risks, not device management.
  • C. Microsoft Defender for Endpoint is an enterprise endpoint security platform that provides preventative protection, post-breach detection, automated investigation, and response.
  • D. Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides visibility, control, and protection for cloud applications.

Microsoft Intune

A cloud-based service for unified endpoint management (UEM) that helps manage devices and applications.

  • Manages corporate and personal devices (BYOD).
  • Deploys applications and enforces security policies.
  • Part of Microsoft Endpoint Manager.

Memory trick: Intune integrates devices, apps, and policies for seamless endpoint control.

More Describe the capabilities of Microsoft Security solutions questions