Scenarios supported by compliant network check in Global Secure Access

Evaluate solutions for network security and Security Service Edge (SSE)
Answer Correct answer: A, D — Compliant network check supports cloud apps like the third-party SaaS app and on-prem apps via app proxy; it does not apply to source computers or CAE.

Your company has a main office and a branch office. The main office contains 20 on-premises servers that run Windows Server and host apps that are published by using Microsoft Entra application proxy. The main office contains 500 on-premises computers that run Windows 11. The branch office contains 100 on-premises computers that run Windows 11. All the main office computers are enrolled in Microsoft Intune. The branch office computers are NOT enrolled in Intune. You have a Microsoft 365 ES subscription. You have a Microsoft Entra tenant. You have a third-party software as a service (SaaS) app that is registered in the Microsoft Entra tenant. You plan to implement Global Secure Access. You are evaluating the use of compliant network check and Conditional Access. Which two scenarios are supported by compliant network check? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point

  1. connections to the third-party SaaS app Correct Answer
  2. connections from the branch office computers
  3. Continuous Access Evaluation for Microsoft Exchange Online
  4. connections to the on-premises apps Correct Answer

Community Votes

AC
55%
AD
45%

55% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Compliant network check requires the destination app to be Entra ID-integrated (cloud app) or app-proxy-published (on-prem); branch-office computers and CAE for Exchange are not compliant-network-check scenarios.

Compliant network check in Microsoft Entra Global Secure Access is supported for connections to Entra ID cloud apps such as a third-party SaaS app registered in Entra and for on-premises apps published through the Entra application proxy; it is not a per-computer or CAE feature.

Selecting connections from branch-office computers (B) or CAE for Exchange Online (C) — compliant network check evaluates destination-app trust, not source computers, and is separate from Continuous Access Evaluation.

Community Discussion (5 comments)

424ede1 👍 2 Selected: AC
Browse to Global Secure Access > Settings > Session management > Adaptive access. Select the toggle to Enable CA Signaling for Entra ID (covering all cloud apps). This will automatically enable CAE signaling for Office 365. If your organization is enrolling devices into Microsoft Intune, it is recommended to exclude the applications Microsoft Intune Enrollment and Microsoft Intune from your Conditional Access policy to avoid a circular dependency. https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-compliant-network#enable-global-secure-access-signaling-for-conditional-access
SMHcalicut 👍 1 Selected: AD
Continuous Access Evaluation (CAE) is a feature that provides real-time access decisions based on user and device state changes. While CAE enhances security, it is not directly related to compliant network checks
sweetykaur 👍 4 Selected: AD
A. connections to the third-party SaaS app D. connections to the on-premises apps Compliant network check ensures that devices meet specific security requirements before allowing connections to certain applications. This helps enforce security policies and control access to both third-party SaaS apps and on-premises applications.
reyreyg 👍 2 Selected: AC
Answer correct https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-compliant-network
676ae1a 👍 2 Selected: AC
Conexiones a la aplicación SaaS de terceros: Permite garantizar que solo las conexiones desde redes seguras puedan acceder a la aplicación SaaS, mejorando la seguridad general. Conexiones a las aplicaciones locales: Ayuda a asegurar que solo usuarios y dispositivos en ubicaciones seguras puedan acceder a las aplicaciones locales publicadas mediante el proxy de aplicación.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Entra Global Secure Access compliant network check works for apps that are Entra ID-integrated cloud apps (such as the third-party SaaS app registered in Entra, option A) and for on-premises apps published through the Entra application proxy (option D). It lets Conditional Access trust that the connection originated from a compliant network.

Why the Other Options Are Wrong

Connections from the branch-office computers (B) are about the source device, not a destination app supported by compliant network check, and those computers are not even Intune-enrolled. Continuous Access Evaluation for Exchange Online (C) is a separate real-time reevaluation feature, not a compliant-network-check scenario.

Community Comment Notes

The community favored A and D (55 votes). Comments cite the compliant-network documentation confirming it covers cloud apps and app-proxy-published on-prem apps; a minority (AD 45) included CAE, which is a distinct feature.

Official Reference

Related Analysis

Practice All SC-100 Questions

Access 110 questions with complete answers and detailed explanations.

View Full SC-100 Practice Test →

← Back to SC-100 Study Guide