Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityHard

A global organization uses Microsoft 365 and Azure services. They want to ensure that employees can only access sensitive data from managed devices located within specific geographical regions during business hours. Access from unmanaged devices or outside business hours should be blocked or require additional verification. Which identity concept would best facilitate this granular access control?

  1. ASingle Sign-On (SSO)
  2. BRole-Based Access Control (RBAC)
  3. CJust-in-Time (JIT) Access
  4. DConditional Access
Show answer & explanation

Correct answer: D. Conditional Access

Conditional Access evaluates conditions like user location, device state, and sign-in risk during authentication to enforce access policies. This allows for granular control, such as blocking access or requiring MFA based on specific criteria.

Why the other options are wrong

  • A. SSO simplifies login but doesn't provide the granular, condition-based access control described.
  • B. RBAC grants permissions based on roles, but doesn't dynamically evaluate conditions like device state or location for access decisions.
  • C. JIT Access grants temporary, elevated permissions for specific tasks, which is a different concept from dynamic access control based on environmental conditions.

Conditional Access

A security feature that evaluates specific conditions (e.g., user, location, device, risk) to determine if and how a user can access a resource.

  • Enforces policies based on real-time conditions.
  • Can block access, require MFA, or limit capabilities.
  • Integrates with identity providers and device management.

Memory trick: Conditional Access Adjusts to Context

More Describe the concepts of security, compliance, and identity questions