Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraEasy

A company is implementing Microsoft Entra ID and wants to ensure that users can only access cloud applications from devices that are marked as compliant by Microsoft Intune. Which Microsoft Entra capability should they configure?

  1. AMicrosoft Entra Identity Protection
  2. BMicrosoft Entra Conditional Access
  3. CMicrosoft Entra Privileged Identity Management (PIM)
  4. DMicrosoft Entra Entitlement Management
Show answer & explanation

Correct answer: B. Microsoft Entra Conditional Access

Microsoft Entra Conditional Access allows organizations to enforce policies based on various conditions, including device compliance. By integrating with Microsoft Intune, it ensures that only compliant devices can access resources.

Why the other options are wrong

  • A. Identity Protection focuses on detecting and remediating identity-based risks, not device compliance.
  • C. PIM manages access to privileged roles and is not directly related to device compliance for general user access.
  • D. Entitlement Management streamlines access requests and approvals, not device compliance enforcement.

Microsoft Entra Conditional Access

A feature that allows administrators to enforce policies for accessing resources based on various conditions like user, location, device, and application.

  • Enables granular access control
  • Integrates with other Microsoft services like Intune
  • Supports Zero Trust principles

Memory trick: Conditions dictate who gets through the access gate.

More Describe the capabilities of Microsoft Entra questions