Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantEasy

A Microsoft 365 administrator is setting up a new tenant and needs to ensure that users can only access Microsoft 365 services from trusted devices and approved network locations. Users attempting to access from untrusted devices or unknown locations should be blocked. The company has a Microsoft 365 E5 subscription. Which Azure AD feature should the administrator implement to achieve this granular access control?

  1. AAzure AD Identity Protection
  2. BAzure AD Conditional Access
  3. CAzure AD Privileged Identity Management (PIM)
  4. DAzure AD Multi-Factor Authentication (MFA)
Show answer & explanation

Correct answer: B. Azure AD Conditional Access

Azure AD Conditional Access policies allow administrators to define 'if-then' statements to control access to resources based on specific conditions, such as user location, device state, or application. This directly addresses the requirement to block access from untrusted devices or unknown locations while permitting access from trusted ones.

Why the other options are wrong

  • A. Identity Protection focuses on detecting and remediating identity-based risks, not primarily on granular access control based on device/location trust.
  • C. PIM manages just-in-time access for privileged roles, not general user access based on device/location.
  • D. MFA is a method of authentication, which can be enforced by Conditional Access, but it's not the feature that defines the 'if-then' rules for access based on device/location.

Azure AD Conditional Access

Azure AD Conditional Access is a policy-based security feature that evaluates specific conditions (who, what, where, how) to make real-time access decisions to cloud apps. It allows administrators to enforce controls like MFA, device compliance, or block access entirely based on these conditions.

  • Uses 'if-then' statements (conditions, controls, grants/blocks).
  • Conditions can include user, group, cloud app, device platform, location, client app, sign-in risk, device state.
  • Controls include require MFA, require device to be marked as compliant, require hybrid Azure AD join, require approved client app, grant/block access.
  • Requires Azure AD Premium P1 or P2 licensing (included in Microsoft 365 E5).

Memory trick: Conditions met, access granted; if not, access is supplanted.

More Deploy and manage a Microsoft 365 tenant questions