Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityEasy

A global organization is implementing a security strategy to protect its intellectual property. They want to ensure that access to highly sensitive design documents is granted only after verifying multiple attributes about the user, their device, and their location. Which security concept does this scenario primarily describe?

  1. ARole-Based Access Control (RBAC)
  2. BConditional Access
  3. CMulti-Factor Authentication (MFA)
  4. DLeast Privilege
Show answer & explanation

Correct answer: B. Conditional Access

Conditional Access policies evaluate multiple signals (user, device, location, app, data sensitivity) to make real-time access decisions. This allows for dynamic control over who can access what, and under what conditions, which aligns with the scenario's requirement for verifying multiple attributes before granting access.

Why the other options are wrong

  • A. RBAC assigns permissions based on job functions, which is more static than the dynamic evaluation described.
  • C. MFA verifies user identity through multiple factors, but doesn't inherently consider device or location as part of the access decision process itself.
  • D. Least Privilege focuses on granting only the minimum necessary permissions, not on dynamic access decisions based on conditions.

Conditional Access

A security policy engine that evaluates multiple signals to make real-time access decisions and enforce organizational policies.

  • Combines signals like user, device, location, and application.
  • Enforces access policies based on these conditions.
  • Often used with Azure Active Directory.

Memory trick: Conditional Access is like a smart gatekeeper that checks your entire profile before letting you in.

More Describe the concepts of security, compliance, and identity questions