Capabilities of a User-Registered Device in Microsoft Entra ID

entra-device-identity
Answer Correct answer: A — authenticating to cloud resources by using single sign-on (SSO)

You have a Microsoft Entra tenant named contoso.com that contains a Windows 11 device named Device1 and a user named User1. User1 registers Device1 in contoso.com. Which capability is available to Device1 after registering in contoso.com?

  1. authenticating to cloud resources by using single sign-on (SSO) Correct Answer
  2. enforcing compliance policies
  3. enforcing software updates
  4. enforcing hard drive encryption

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the distinction between 'registration' and 'enrollment'; registration grants SSO access, while enrollment is required for compliance policies, updates, and encryption enforcement.

This question evaluates the specific capabilities granted to a Windows 11 device when registered as a user-owned device in a Microsoft Entra tenant. It establishes that registration primarily enables Single Sign-On (SSO) for cloud resources, distinct from full management features.

Many learners select 'Enforcing compliance policies' because they confuse user registration with full Intune enrollment. Registration alone does not allow the organization to enforce security policies like encryption or updates.

Community Discussion (3 comments)

Moot2 👍 3 Selected: A
I'd say A, what capaibility is available so SSO is. The other options would need you to configure such policies which the question doesn't mention
JayHall 👍 4
Answer is correct: authenticating to cloud resources by using single sign-on (SSO) After Device1 is registered in the Microsoft Entra tenant contoso.com, it gains several capabilities: Single Sign-On (SSO): Device1 can use SSO to access cloud resources seamlessly. Conditional Access: Device1 can be subject to Conditional Access policies, which help secure access to resources based on device compliance. Mobile Device Management (MDM): If enrolled in MDM (e.g., Microsoft Intune), Device1 can have organization-required configurations enforced, such as password complexity and encryption. Access to Organizational Resources: Device1 can access resources in the organization based on the Microsoft Entra account. https://learn.microsoft.com/en-us/entra/identity/devices/concept-device-registration
HvD 👍 2
B should be my answer. A registered user/device can access company data when it meets compliancy and/or getting through ConditionalAccess. There is no SSO with such a registered device.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

When a user registers a personal device (BYOD) in Microsoft Entra ID, the primary capability granted is Single Sign-On (SSO). This allows the device to use its corporate identity to access cloud resources seamlessly without requiring full device management. The registration process links the device's local account to the Entra ID, enabling authentication flows.

Why the Other Options Are Wrong

Options B, C, and D refer to capabilities that require the device to be enrolled in Microsoft Intune, not just registered. Enforcement of compliance policies, software updates, and hard drive encryption are managed via Intune configuration profiles and policies, which are not applied to devices that are only registered in Entra ID.

Community Comment Notes

Community consensus strongly supports Option A, noting that SSO is the direct result of registration. One commenter noted that other options require configured policies, implying enrollment. Another dissenting view suggested compliance, but this is incorrect because conditional access checks compliance, but does not enforce it on a non-enrolled device.

Exam Strategy

Always distinguish between 'register' (user-owned, limited access/SSO) and 'enroll' (organization-managed, full control/policies). If the question mentions 'register', think SSO and Conditional Access evaluation; if it mentions 'enroll', think policy enforcement and remote actions.

Frequently Asked Questions

Can a registered device be subject to Conditional Access?

Yes, Conditional Access policies can evaluate device state (registered vs. compliant), but the device itself cannot enforce policies like encryption.

What is the difference between registration and enrollment?

Registration links the device to Entra ID for SSO; Enrollment adds the device to Intune for management and policy enforcement.

Related Analysis

Practice All MD-102 Questions

Access 92 questions with complete answers and detailed explanations.

View Full MD-102 Practice Test →

← Back to MD-102 Study Guide