Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium

A company is implementing a Zero Trust security model. They want to ensure that all access requests are evaluated against user identity, location, device health, and application sensitivity in real-time, and then enforce appropriate access controls like MFA or blocking access. Which Microsoft Entra capability is best suited for this dynamic policy enforcement?

  1. AMicrosoft Entra Access Reviews
  2. BMicrosoft Entra Conditional Access
  3. CMicrosoft Entra Identity Protection
  4. DMicrosoft Entra PIM (Privileged Identity Management)
Show answer & explanation

Correct answer: B. Microsoft Entra Conditional Access

Microsoft Entra Conditional Access allows organizations to enforce policies based on various conditions such as user identity, location, device state, and application, enabling dynamic access control decisions critical for a Zero Trust model.

Why the other options are wrong

  • A. Access Reviews periodically verify existing access, not real-time access decisions.
  • C. Identity Protection detects risks, but Conditional Access is the engine that enforces policies based on those risks and other conditions.
  • D. PIM manages privileged roles, not dynamic access policies for all users.

Microsoft Entra Conditional Access

A policy-based access control engine that enables organizations to enforce rules based on various conditions (user, location, device, application) to determine if and how a user can access a resource.

  • Key component of a Zero Trust security model.
  • Evaluates conditions in real-time during sign-in.
  • Can enforce actions like MFA, blocking access, or requiring compliant devices.
  • Works with Microsoft Entra Identity Protection for risk-based policies.

Memory trick: Conditional Access: The 'if-then' security guard for your data.

More Describe the capabilities of Microsoft Entra questions