nerdexam
Microsoft

SC-900 · Question #77

Which Microsoft Entra feature can you use to restrict Microsoft Intune-managed devices from accessing corporate resources?

The correct answer is C. conditional access policies. Conditional Access policies in Microsoft Entra ID allow administrators to enforce access controls based on specific conditions - such as device compliance status, user identity, location, or application being accessed. When integrated with Microsoft Intune, Conditional Access…

Submitted by kwame.gh· Apr 18, 2026Describe the capabilities of Microsoft Entra

Question

Which Microsoft Entra feature can you use to restrict Microsoft Intune-managed devices from accessing corporate resources?

Options

  • Anetwork security groups (NSGs)
  • BMicrosoft Entra Privileged Identity Management (PIM)
  • Cconditional access policies
  • Dresource locks

How the community answered

(41 responses)
  • A
    5% (2)
  • C
    93% (38)
  • D
    2% (1)

Explanation

Conditional Access policies in Microsoft Entra ID allow administrators to enforce access controls based on specific conditions - such as device compliance status, user identity, location, or application being accessed. When integrated with Microsoft Intune, Conditional Access can require devices to be Intune-compliant before granting access to corporate resources, effectively restricting non-compliant or unmanaged devices. NSGs (A) control network traffic at the subnet/NIC level and are not Entra features. PIM (B) manages privileged role assignments, not device-based access. Resource locks (D) prevent accidental deletion or modification of Azure resources, not access control.

Topics

#Microsoft Entra Conditional Access#Device compliance#Access control#Intune

Community Discussion

No community discussion yet for this question.

Full SC-900 Practice