Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Medium

A Microsoft 365 Endpoint Administrator is configuring a new Conditional Access policy. The policy needs to ensure that users can only access Microsoft 365 services from devices that are either marked as compliant by Intune or hybrid Azure AD joined. Which condition should the administrator configure in the Conditional Access policy?

  1. ADevice state
  2. BClient apps
  3. CDevice platforms
  4. DGrant control
Show answer & explanation

Correct answer: A. Device state

The 'Device state' condition in Conditional Access allows administrators to specify requirements for devices to be either 'Marked as compliant' by Intune or 'Hybrid Azure AD joined' to grant access to resources.

Why the other options are wrong

  • B. Client apps condition targets specific applications (e.g., browser, mobile apps) used to access resources, not the device's state.
  • C. Device platforms condition targets specific operating systems (e.g., Windows, iOS), not the compliance or join state of the device.
  • D. Grant control is an access control that decides what happens if conditions are met, not a condition itself.

Conditional Access Device State

The Device state condition in Conditional Access allows policies to evaluate if a device is compliant with Intune policies or if it is hybrid Azure AD joined, which are crucial for secure access.

  • Evaluates if a device is 'Marked as compliant' by Intune.
  • Evaluates if a device is 'Hybrid Azure AD joined'.
  • Essential for 'Require compliant device' grant control.

Memory trick: To access the exclusive club, your device's 'state' must be elite: compliant or hybrid joined.

More Manage identity and compliance (10-15%) questions