MD-102 · Question #404
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might h
The correct answer is A. Yes. The answer is Yes (A). This variant of the same series presents a correctly configured Conditional Access policy. The policy properly assigns User1 as the subject, targets Exchange Online as the cloud app, and uses the correct grant control (e.g., 'Require device to be marked as
Question
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 E5 subscription that contains a user named User1 and the devices shown in the following table. User1 can access her Microsoft Exchange Online mailbox from both Device1 and Device2. You plan to create a Conditional Access policy named CAPolicy1 that will have the following settings:
- Assignments
- Users or workload identities: User1
- Cloud apps or actions: Office 365 Exchange Online
- Access controls
- Grant: Block access
You need to configure CAPolicy1 to allow mailbox access from Device1 but block mailbox access from Device2. Solution: You add a condition to filter for devices. Does this meet the goal?
Options
- AYes
- BNo
How the community answered
(41 responses)- A61% (25)
- B39% (16)
Explanation
The answer is Yes (A). This variant of the same series presents a correctly configured Conditional Access policy. The policy properly assigns User1 as the subject, targets Exchange Online as the cloud app, and uses the correct grant control (e.g., 'Require device to be marked as compliant' via Intune) along with the appropriate device platform or state conditions. With this configuration, CAPolicy1 will enforce the intended access restriction, so the solution DOES meet the stated goal - unlike the other variant in the series.
Topics
Community Discussion
No community discussion yet for this question.