nerdexam
Microsoft

SC-300 · Question #27

You have a Microsoft 365 tenant. All users have computers that run Windows 10. Most computers are company-owned and joined to Azure Active Directory (Azure AD). Some computers are user-owned and are…

The correct answer is B. an Azure AD conditional access policy that has session controls configured. You need to use "Use app enforced restrictions" from the "Session" control of the CA. https://docs.microsoft.com/en-us/sharepoint/control-access-from-unmanaged-devices

Submitted by kwame.gh· Mar 6, 2026Implement access management for apps

Question

You have a Microsoft 365 tenant. All users have computers that run Windows 10. Most computers are company-owned and joined to Azure Active Directory (Azure AD). Some computers are user-owned and are only registered in Azure AD. You need to prevent users who connect to Microsoft SharePoint Online on their user-owned computer from downloading or syncing files. Other users must NOT be restricted. Which policy type should you create?

Options

  • Aa Microsoft Cloud App Security activity policy that has Microsoft Office 365 governance actions
  • Ban Azure AD conditional access policy that has session controls configured
  • Can Azure AD conditional access policy that has client apps conditions configured
  • Da Microsoft Cloud App Security app discovery policy that has governance actions configured

How the community answered

(25 responses)
  • A
    20% (5)
  • B
    68% (17)
  • C
    4% (1)
  • D
    8% (2)

Explanation

You need to use "Use app enforced restrictions" from the "Session" control of the CA. https://docs.microsoft.com/en-us/sharepoint/control-access-from-unmanaged-devices

Topics

#Conditional Access#Session controls#Device state#SharePoint Online#Data exfiltration prevention

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice