Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium
A global manufacturing company uses Azure AD and has multiple custom applications registered. They need to ensure that users from a specific department can only access one of these custom applications from devices that are marked as 'compliant' by Microsoft Intune. All other users should have unrestricted access to this application. Which Azure AD feature should be configured?
- AConditional Access
- BPrivileged Identity Management (PIM)
- CIdentity Protection
- DAccess Reviews
Show answer & explanationAnswer & explanation
Correct answer: A. Conditional Access
Conditional Access policies in Azure AD allow administrators to enforce specific conditions for accessing resources, such as requiring compliant devices or restricting access based on user groups and applications. This directly addresses the requirement for department-specific compliant device access.
Why the other options are wrong
- B. Privileged Identity Management (PIM) manages, controls, and monitors access to important resources by providing just-in-time access, not for device compliance requirements.
- C. Identity Protection focuses on detecting and preventing identity-based risks, not on enforcing device compliance for application access.
- D. Access Reviews help manage group memberships and access to applications by periodically reviewing who has access, not by enforcing device compliance.
Azure AD Conditional Access
A feature of Azure Active Directory that enables organizations to enforce policies based on specific conditions, such as user location, device state, or application being accessed, to control access to resources.
- Granular control over resource access.
- Integrates with device compliance (e.g., Intune).
- Can enforce multi-factor authentication, compliant devices, etc.
Memory trick: Conditional Access is like a bouncer checking IDs and dress codes at the door.