Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantHard

A Microsoft 365 administrator is implementing a new security policy that requires all users accessing SharePoint Online from unmanaged devices to use a session with restricted capabilities, such as preventing downloads and requiring web-only access. Which Azure AD feature should the administrator configure to enforce this policy?

  1. AAzure AD Identity Protection
  2. BAzure AD Conditional Access policies
  3. CAzure AD Privileged Identity Management (PIM)
  4. DMicrosoft Defender for Cloud Apps (MDCA)
Show answer & explanation

Correct answer: B. Azure AD Conditional Access policies

Azure AD Conditional Access policies, when integrated with Microsoft Defender for Cloud Apps (MDCA) for session control, can enforce restrictions like preventing downloads and ensuring web-only access for users on unmanaged devices. This allows for granular control over session behavior based on device state.

Why the other options are wrong

  • A. Identity Protection focuses on detecting and remediating identity-based risks, not session control for unmanaged devices.
  • C. PIM manages just-in-time access for privileged roles, not session restrictions for unmanaged devices.
  • D. MDCA provides the *session control capabilities* (e.g., blocking downloads), but Conditional Access is the *policy engine* that applies these controls based on conditions.

Azure AD Conditional Access (with MDCA Session Control)

An Azure AD feature that evaluates conditions (e.g., user, device, location) and, if met, enforces specific access controls, including integrating with Microsoft Defender for Cloud Apps for advanced session-level restrictions.

  • Requires Azure AD Premium P1 and MDCA license.
  • Can apply session controls like 'Block downloads' or 'Require web-only access'.
  • Used to enforce security policies based on device compliance or management status.

Memory trick: Conditional Access is the smart bouncer at the cloud club, checking your device's ID and setting rules for your session.

More Deploy and manage a Microsoft 365 tenant questions