Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium
A company is implementing a Zero Trust security model. They need to ensure that every access request to a resource is explicitly verified, regardless of whether the request originates from inside or outside the network. This verification must consider user identity, device health, location, application sensitivity, and data classification before granting access. Which core Microsoft Entra capability underpins this 'Verify Explicitly' principle?
- AMicrosoft Entra Password Protection
- BMicrosoft Entra Conditional Access
- CMicrosoft Entra Identity Protection
- DMicrosoft Entra Security Defaults
Show answer & explanationAnswer & explanation
Correct answer: B. Microsoft Entra Conditional Access
Microsoft Entra Conditional Access is the policy engine that allows organizations to implement the 'Verify Explicitly' principle of Zero Trust by evaluating multiple signals (user, device, location, app, data) to make real-time access decisions.
Why the other options are wrong
- A. Password Protection prevents weak or banned passwords from being used.
- C. Identity Protection detects and remediates identity-based risks, feeding into Conditional Access.
- D. Security Defaults are a baseline set of security policies for all tenants, less granular.
Microsoft Entra Conditional Access
A policy-based engine that evaluates signals (user, device, location, application, data sensitivity) to make real-time access decisions and enforce organizational access policies.
- Central to implementing Zero Trust 'Verify Explicitly' principle
- Combines multiple signals to determine if access should be granted, denied, or challenged
- Can enforce MFA, device compliance, approved client apps, and more
Memory trick: Conditional Access checks all conditions before letting you pass.