Your organization will allow Azure Virtual Desktop access only from corporate-managed Windows devices that are both hybrid Azure AD joined and Intune-compliant. Which two Conditional Access grant controls should you require to enforce this? (Each correct answer presents part of the solution. Choose two answers.)
Choose an answer
Tap an option to check your answer.
Correct answer: Require device to be marked as compliant, Require Hybrid Azure AD joined device.
Why this is the answer
To enforce access only from corporate-managed Windows devices that are hybrid Azure AD joined and Intune-compliant, you must configure two specific Conditional Access grant controls. "Require device to be marked as compliant" ensures that only devices meeting your Intune compliance policies (e.g., OS version, antivirus status) can access Azure Virtual Desktop. "Require Hybrid Azure AD joined device" restricts access to devices registered with both your on-premises Active Directory and Azure AD, confirming they are corporate-managed. "Require app protection policy" is for mobile application management (MAM) and doesn't apply to Windows devices accessing AVD. "Require password change" is a user-based control, not device-based. "Require all apps to use approved client apps" is for restricting access to specific client applications, not for device compliance or join status.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed