Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam SC-300 topic 2 question 77 discussion

Actual exam question from Microsoft's SC-300
Question #: 77
Topic #: 2
[All SC-300 Questions]

You have a Microsoft 365 E5 subscription that contains three users named User1, User2, and User3 and a Microsoft SharePoint Online site named Site1.

The subscription contains the devices shown in the following table.



The users sign in to the devices as shown in the following table.



You have a Conditional Access policy that has the following settings:

• Name: CA1
• Assignments
o Users and groups: User1, User2, User3
o Cloud apps or actions: SharePoint - Site1
• Access controls
o Session: Use app enforced restrictions

From the SharePoint admin center, you configure Access control for unmanaged devices to allow limited, web-only access.

Which users will have full access to Site1?

  • A. User1 only
  • B. User2 only
  • C. User3only
  • D. User1 and User2 only
  • E. User1, User2, and User3
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
jlbrandes
Highly Voted 6 months ago
Selected Answer: A
Only Joined devices are managed. https://learn.microsoft.com/en-us/microsoft-365/business-premium/m365bp-managed-unmanaged-devices?view=o365-worldwide&tabs=Managed
upvoted 10 times
...
vaaws
Highly Voted 6 months, 2 weeks ago
The users who will have full access to Site1 are User1 and User2 only. The Conditional Access policy is configured to include User1, User2, and User3, but the Access control for unmanaged devices in the SharePoint admin center allows only limited, web-only access. Therefore, only User1 and User2, who sign in from managed devices, will have full access to Site1. The correct answer is D. User1 and User2 only.
upvoted 9 times
...
AleFerrillo
Most Recent 1 week, 3 days ago
Selected Answer: B
The key here is the compliancy status. "you can block or limit access to SharePoint and OneDrive content from unmanaged devices (those not hybrid AD joined or compliant in Intune)" so any compliant device is considered Managed and any non-compliant is considered Unmanaged.
upvoted 2 times
...
bpaccount
2 weeks, 1 day ago
Selected Answer: B
I thinks its B also.
upvoted 1 times
...
KRISTINMERIEANN
1 month, 1 week ago
Selected Answer: A
https://learn.microsoft.com/en-us/microsoft-365/business-premium/m365bp-managed-unmanaged-devices?view=o365-worldwide&tabs=Managed
upvoted 1 times
...
HartMS
1 month, 2 weeks ago
Option B: User2 Only User 1 will have full access. Since this policy restricts the access for unmanaged devices. Joined = Managed Registered = Unmanaged The compliance does not matter since "Device requires to be marked as Compliant" is not a criteria here.
upvoted 1 times
HartMS
1 month, 2 weeks ago
Correcting myself: Option A: User 1 Only
upvoted 1 times
...
...
e56f13e
1 month, 2 weeks ago
Selected Answer: B
https://learn.microsoft.com/en-us/sharepoint/control-access-from-unmanaged-devices As a SharePoint Administrator or Global Administrator in Microsoft 365, you can block or limit access to SharePoint and OneDrive content from unmanaged devices (those not hybrid AD joined or compliant in Intune).
upvoted 1 times
...
e56f13e
1 month, 2 weeks ago
Correct answer is definitely B: https://learn.microsoft.com/en-us/sharepoint/control-access-from-unmanaged-devices As a SharePoint Administrator or Global Administrator in Microsoft 365, you can block or limit access to SharePoint and OneDrive content from unmanaged devices (those not hybrid AD joined or compliant in Intune).
upvoted 1 times
...
belyo
2 months, 1 week ago
Selected Answer: B
User1 is using Device1, which is joined but non-compliant. Since the device is non-compliant, User1 will have limited, web-only access to Site1 due to the SharePoint Access control settings.
upvoted 2 times
...
Ody
2 months, 4 weeks ago
Gotta love Micrsoft exams. This implies none of them have access. As a SharePoint Administrator or Global Administrator in Microsoft 365, you can block or limit access to SharePoint and OneDrive content from unmanaged devices (those not hybrid AD joined or compliant in Intune). https://learn.microsoft.com/en-us/sharepoint/control-access-from-unmanaged-devices
upvoted 1 times
...
loaysalameh
3 months, 1 week ago
Selected Answer: B
The answer is correct. The not compliant devise is unmanaged The registered device is managed. The not registered not joined is unmanaged.
upvoted 2 times
...
Sneekygeek
3 months, 2 weeks ago
Selected Answer: B
The wording here implies that any compliant device is considered 'managed' by SPO - "As a SharePoint Administrator or Global Administrator in Microsoft 365, you can block or limit access to SharePoint and OneDrive content from unmanaged devices (those not hybrid AD joined or compliant in Intune)" https://learn.microsoft.com/en-us/sharepoint/control-access-from-unmanaged-devices
upvoted 2 times
...
Doinitza
3 months, 2 weeks ago
Selected Answer: D
In Access control, in SharePoint admin center, it clearly shows “Unmanaged devices => Restrict access from devices that aren’t compliant or joined to a domain”
upvoted 1 times
...
milosp
5 months, 2 weeks ago
Selected Answer: B
Let’s analyze each user: User1 is using Device1, which is joined but non-compliant. Since the device is non-compliant, User1 will have limited, web-only access to Site1 due to the SharePoint Access control settings. User2 is using Device2, which is registered and compliant. Since the device is compliant, User2 will have full access to Site1. User3 is using Device3, which is not joined or registered. Since the device is unmanaged, User3 will have limited, web-only access to Site1 due to the SharePoint Access control settings. So, the answer is: B. User2 only
upvoted 2 times
...
Nivos300
6 months, 1 week ago
Selected Answer: B
B. User2 only Here's the reasoning: The Conditional Access policy (CA1) is assigned to User1, User2, and User3. The policy's access control is set to "Session: Use app enforced restrictions." Now, let's look at the device compliance status and user-device assignments: Device1 is joined but noncompliant. Device2 is registered and compliant. Device3 is none (not applicable). Since the access control is set to "Session: Use app enforced restrictions," unmanaged or noncompliant devices will have limited, web-only access. Device1 is noncompliant, so User1 (Device1) will have limited access. Device3 is not applicable, so User3 (Device3) is not relevant to this scenario.
upvoted 3 times
Nivos300
6 months, 1 week ago
Continued User2 (Device2) is using a registered and compliant device, so User2 will have full access to Site1. Therefore, User2 (full access) will be the only user with full access to Site1, while User1 and User3 will have limited access or not be affected by the Conditional Access policy.
upvoted 1 times
...
...
JCkD4Ni3L
6 months, 3 weeks ago
Selected Answer: A
Only User1 will have full access since Device1 is the only Azure AD Joined device (Managed)
upvoted 3 times
...
einkaufacs
6 months, 3 weeks ago
A registered device, which is also integrated and compliant in Intune should work here. So the answer seems plausible to me. https://learn.microsoft.com/en-us/sharepoint/control-access-from-unmanaged-devices
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...