Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraHard

A company is implementing a Zero Trust security model and wants to ensure that all user access requests are continuously evaluated and validated in real-time, even after initial authentication. This includes verifying device health, user location, and application security posture for every access attempt. Which core Microsoft Entra principle aligns with this continuous validation approach?

  1. AVerify Explicitly
  2. BLeast Privilege Access
  3. CAssume Breach
  4. DSingle Sign-On (SSO)
Show answer & explanation

Correct answer: A. Verify Explicitly

The 'Verify Explicitly' principle of Zero Trust dictates that all access attempts must be explicitly authenticated and authorized based on all available data points, including user identity, location, device health, service, and data classification. This aligns with continuous real-time validation.

Why the other options are wrong

  • B. Least Privilege Access ensures users have only the minimum necessary permissions, but doesn't describe the continuous validation process itself.
  • C. Assume Breach is a mindset for preparing for security incidents, not a real-time validation principle.
  • D. SSO enables seamless access but doesn't inherently imply continuous, real-time validation against Zero Trust principles.

Zero Trust Principle: Verify Explicitly

The Zero Trust principle that requires all access requests to be explicitly authenticated and authorized based on all available data points.

  • No implicit trust is granted to any user, device, or service.
  • Access decisions are made in real-time based on context.
  • Verifies identity, device health, location, data classification, and more.

Memory trick: Zero Trust means 'Never Trust, Always Verify' – it's like a strict bouncer at every door.

More Describe the capabilities of Microsoft Entra questions