nerdexam
Microsoft

SC-300 · Question #443

Hotspot Question Your network contains an on-premises Active Directory Domain Services (AD DS) domain. The domain contains 500 Windows 11 devices. You have a Microsoft 365 subscription that syncs…

The correct answer is Apply Policy1 to all the Windows devices:: Microsoft Entra hybrid join the devices to the subscription.; Assess the compliance of the Windows devices with Policy1:: Enroll the devices in Microsoft Intune. This question tests knowledge of Conditional Access policy assignment and device compliance assessment in a hybrid Azure AD environment with Microsoft 365. You must know how to target policies to hybrid-joined Windows devices and how to evaluate compliance using Microsoft Intune.

Submitted by emma.c· Mar 6, 2026Implement authentication and access management

Question

Hotspot Question Your network contains an on-premises Active Directory Domain Services (AD DS) domain. The domain contains 500 Windows 11 devices. You have a Microsoft 365 subscription that syncs with the domain. You create a Conditional Access policy named Policy1. You need to meet the following requirements:

  • Apply Policy1 to all the Windows devices.
  • Assess the compliance of the Windows devices with Policy1.

What should you do for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Answer:

Answer Area

  • Apply Policy1 to all the Windows devices:Microsoft Entra hybrid join the devices to the subscription.
    Microsoft Entra hybrid join the devices to the subscription.Microsoft Entra join the devices to the subscription.Microsoft Entra register the devices to the subscription.
  • Assess the compliance of the Windows devices with Policy1:Enroll the devices in Microsoft Intune.
    Enroll the devices in Microsoft Intune.Onboard the devices to Microsoft Defender for Endpoint.Onboard the devices to Microsoft Purview.

How the community answered

(1 responses)
  • Admin1|Enroll the devices in Microsoft Intune.
    100% (1)

Explanation

This question tests knowledge of Conditional Access policy assignment and device compliance assessment in a hybrid Azure AD environment with Microsoft 365. You must know how to target policies to hybrid-joined Windows devices and how to evaluate compliance using Microsoft Intune.

Approach. To apply Policy1 to all Windows devices in a hybrid environment, you should configure the Conditional Access policy assignment to target 'All devices' or specifically filter for Windows platforms under the 'Device platforms' condition - this ensures all 500 Windows 11 hybrid Azure AD-joined devices are in scope. To assess compliance of these devices with Policy1, you need to enroll the devices in Microsoft Intune and create a compliance policy in Intune; Intune evaluates each device against defined compliance rules and reports compliance state, which Conditional Access then uses as a condition (Require device to be marked as compliant). The devices must be hybrid Azure AD joined (already synced from on-premises AD DS) and enrolled in Intune for compliance evaluation to work. Without Intune enrollment and a compliance policy, Conditional Access cannot assess whether a device is compliant.

Concept tested. Conditional Access policy scoping using device platform filters and Microsoft Intune device compliance policy enrollment for hybrid Azure AD-joined Windows 11 devices in a Microsoft 365 environment.

Reference. https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-conditions#device-platforms and https://learn.microsoft.com/en-us/mem/intune/protect/device-compliance-get-started

Topics

#Conditional Access#Microsoft Entra hybrid join#device compliance#Microsoft Intune

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice