Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Medium
A Microsoft 365 Endpoint Administrator needs to configure Microsoft Intune to apply specific security settings to devices based on their geographical location. For example, devices accessing corporate data from outside the corporate network should have a stricter set of security policies applied. Which feature in Microsoft Intune should the administrator use to achieve this dynamic policy application?
- ADevice compliance policies
- BConditional Access policies
- CConfiguration profiles
- DSecurity baselines
Show answer & explanationAnswer & explanation
Correct answer: B. Conditional Access policies
Conditional Access policies are designed to enforce conditions for accessing resources, including location-based restrictions. They work by evaluating signals like user, device, location, and application, then enforcing access decisions.
Why the other options are wrong
- A. Device compliance policies assess a device's health and configuration against a set of rules, but they don't dynamically change settings based on access conditions like location.
- C. Configuration profiles deploy settings to devices but do not dynamically adjust them based on access conditions or location in real-time.
- D. Security baselines are predefined groups of settings that are recommended by Microsoft to secure devices, but they are static and do not adapt based on access location.
Conditional Access Location Condition
A feature within Microsoft Entra Conditional Access that allows administrators to define access policies based on the network location from which a user is attempting to access resources.
- Can restrict access from specific countries/regions.
- Can require MFA when accessing from untrusted locations.
- Requires named locations to be configured in Microsoft Entra ID.
Memory trick: Location locks down access, Conditional Access makes it happen.