Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceEasy
A security administrator needs to ensure that only users accessing Azure resources from corporate-managed devices can access specific sensitive applications. Users from unmanaged devices should be blocked. All users are managed in Azure Active Directory. Which Azure AD feature should be configured to meet this requirement?
- AMulti-Factor Authentication (MFA) enforcement
- BAzure AD Privileged Identity Management (PIM)
- CAzure AD Conditional Access policies
- DAzure AD Identity Protection
Show answer & explanationAnswer & explanation
Correct answer: C. Azure AD Conditional Access policies
Azure AD Conditional Access policies allow administrators to enforce specific access controls based on various conditions, including device state (managed/compliant devices), location, and application being accessed. This directly addresses the requirement to block unmanaged devices.
Why the other options are wrong
- A. MFA enforces an additional verification step but does not differentiate access based on whether a device is corporate-managed or unmanaged.
- B. PIM manages just-in-time access for privileged roles, which is not relevant to device access requirements for all users.
- D. Identity Protection focuses on detecting and remediating identity-based risks, not on enforcing device-based access policies.
Azure AD Conditional Access
A feature of Azure Active Directory that allows organizations to enforce policies for accessing resources based on conditions such as user, device, location, and application.
- Enables fine-grained access control.
- Supports conditions like device state (managed/unmanaged).
- Helps protect sensitive data and applications.
Memory trick: Only trusted devices get the key to the corporate applications.