Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityHard

A multinational corporation needs a way to secure its cloud resources by defining policies that evaluate a user's device health, location, and the sensitivity of the data being accessed in real-time before granting access. Which Azure Active Directory feature is designed to enforce such dynamic access decisions?

  1. AConditional Access
  2. BIdentity Protection
  3. CAzure AD Connect
  4. DPrivileged Identity Management (PIM)
Show answer & explanation

Correct answer: A. Conditional Access

Azure AD Conditional Access allows organizations to enforce policies that evaluate various signals (user, device, location, application, risk) in real-time to make dynamic access decisions. This directly addresses the need to consider device health, location, and data sensitivity for access.

Why the other options are wrong

  • B. Identity Protection detects and remediates identity-based risks, which can feed into Conditional Access but isn't the policy enforcement engine itself.
  • C. Azure AD Connect synchronizes on-premises directories with Azure AD, not for real-time access policy enforcement.
  • D. PIM manages temporary elevated access for administrative roles, not dynamic access based on conditions.

Conditional Access

An Azure Active Directory feature that enables organizations to enforce policies based on various conditions (e.g., user, location, device, application, real-time risk) to make dynamic access decisions and protect resources.

  • Evaluates conditions in real-time.
  • Enables dynamic access decisions (grant, block, MFA).
  • Key component of Zero Trust architecture.

Memory trick: Conditional Access: Like a smart bouncer checking many things (ID, mood, outfit) before letting you in.

More Describe the concepts of security, compliance, and identity questions