Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium

A multinational corporation uses Microsoft Entra ID and wants to ensure that all access to sensitive cloud applications is granted only to devices that are compliant with company security policies. Which Microsoft Entra capability allows them to enforce these device-based restrictions?

  1. AMicrosoft Entra Domain Services
  2. BMicrosoft Entra Conditional Access
  3. CMicrosoft Entra Privileged Identity Management
  4. DMicrosoft Entra Identity Protection
Show answer & explanation

Correct answer: B. Microsoft Entra Conditional Access

Microsoft Entra Conditional Access allows organizations to enforce policies based on various conditions, including device state (e.g., compliant devices), ensuring that access is granted only when specific criteria are met.

Why the other options are wrong

  • A. Domain Services provides managed domain controllers in Azure for legacy applications.
  • C. PIM manages privileged role assignments, not device-based access policies.
  • D. Identity Protection focuses on user risk, not device compliance for access control.

Microsoft Entra Conditional Access

A Microsoft Entra ID capability that brings signals together to make decisions, enforce organizational policies, and help protect organizational resources.

  • Uses 'If-then' statements (If a user wants to access a resource, then they must complete an action).
  • Can enforce MFA, device compliance, trusted locations, and app protection policies.
  • Crucial for implementing Zero Trust principles.

Memory trick: Conditional Access is the traffic cop for your data, directing who goes where based on strict rules.

More Describe the capabilities of Microsoft Entra questions