MS-102 · Question #491
You have a Microsoft 365 tenant. Company policy requires that all Windows 10 devices meet the following minimum requirements: - Require complex passwords. - Require the encryption of data storage…
The correct answer is B. a compliance policy D. a conditional access policy. Two components work together to achieve this: (B) A compliance policy defines the specific rules a device must meet to be considered compliant-such as requiring complex passwords, device encryption, and real-time antivirus protection. (D) A Conditional Access policy enforces…
Question
You have a Microsoft 365 tenant. Company policy requires that all Windows 10 devices meet the following minimum requirements:
- Require complex passwords.
- Require the encryption of data storage devices.
- Have Microsoft Defender Antivirus real-time protection enabled.
You need to prevent devices that do not meet the requirements from accessing resources in the tenant. Which two components should you create? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Options
- Aa configuration policy
- Ba compliance policy
- Ca security baseline profile
- Da conditional access policy
- Ea configuration profile
How the community answered
(56 responses)- A2% (1)
- B84% (47)
- C9% (5)
- E5% (3)
Explanation
Two components work together to achieve this: (B) A compliance policy defines the specific rules a device must meet to be considered compliant-such as requiring complex passwords, device encryption, and real-time antivirus protection. (D) A Conditional Access policy enforces access control based on device compliance status; it grants access to tenant resources only if the device is marked compliant. A compliance policy alone identifies non-compliant devices but does not block them-the Conditional Access policy is what actually enforces the block. Configuration profiles and security baselines push settings to devices but do not enforce access restrictions based on compliance state.
Topics
Community Discussion
No community discussion yet for this question.