Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraHard
A company is implementing a Zero Trust security model. They need a capability that ensures every access request, whether from inside or outside the network, is explicitly verified based on all available data points, including user identity, location, device health, and resource sensitivity. Which Zero Trust principle is being described, and which Microsoft Entra capability is central to its implementation?
- APrinciple: Use Least Privilege Access; Capability: Microsoft Entra Privileged Identity Management (PIM)
- BPrinciple: Assume Breach; Capability: Microsoft Entra Identity Protection
- CPrinciple: Verify Explicitly; Capability: Microsoft Entra Conditional Access
- DPrinciple: Microsegmentation; Capability: Microsoft Entra Application Proxy
Show answer & explanationAnswer & explanation
Correct answer: C. Principle: Verify Explicitly; Capability: Microsoft Entra Conditional Access
The description 'every access request...is explicitly verified based on all available data points' directly aligns with the Zero Trust principle of 'Verify Explicitly'. Microsoft Entra Conditional Access is the primary tool within Microsoft Entra ID that enables this by evaluating various signals (identity, location, device health, etc.) to make access decisions.
Why the other options are wrong
- A. Use Least Privilege Access is a Zero Trust principle, and PIM helps enforce it, but the question describes explicit verification of *every* access, not just privilege elevation.
- B. Assume Breach is a Zero Trust principle, but Identity Protection focuses on risk signals, not comprehensive access decision-making based on all data points.
- D. Microsegmentation is a network security concept, not a direct Microsoft Entra capability for identity verification, and Application Proxy is for secure remote access to on-premises apps.
Zero Trust Principle: Verify Explicitly
Always authenticate and authorize based on all available data points, including user identity, location, device health, service or workload, data classification, and anomalies.
- No implicit trust, even for internal networks
- Authentication and authorization are continuous, not one-time
- Leverages multiple signals for access decisions
Memory trick: Trust no one, check everyone, then give access.