Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsMedium
A government agency is deploying a highly sensitive application to Azure. They require that access to the application is only granted from managed devices that meet specific security standards, and only when users are connecting from within the corporate network or via a compliant VPN connection. Users attempting to access from unmanaged devices or untrusted locations must be blocked. Which Azure service should be configured to enforce these access policies?
- AAzure Active Directory Privileged Identity Management (PIM)
- BAzure Active Directory Conditional Access
- CAzure Active Directory Identity Protection
- DAzure Policy
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Active Directory Conditional Access
Azure Active Directory Conditional Access allows organizations to enforce policies based on conditions such as user, device state (managed/compliant), location (corporate network/VPN), and application. This directly addresses all the requirements for restricting access based on device and network conditions.
Why the other options are wrong
- A. PIM manages just-in-time and time-bound access for privileged roles, which is not the primary mechanism for enforcing access based on device or network conditions for general application access.
- C. Identity Protection focuses on detecting and remediating identity-based risks (e.g., leaked credentials, impossible travel), not on enforcing access based on device or network compliance.
- D. Azure Policy is for enforcing rules and standards on Azure resources (e.g., resource tagging, allowed regions), not for controlling user access to applications based on device or location attributes.
Azure AD Conditional Access
Azure AD Conditional Access is a policy-based access control engine that enables organizations to enforce policies that evaluate signals like user, device, location, and application to make access decisions for cloud apps.
- Enforces access policies based on conditions
- Supports multi-factor authentication (MFA)
- Integrates with Microsoft Intune for device compliance
- Can block or grant access, or require MFA/compliant device
Memory trick: Conditional Access 'Conditions' Your Access.