A security architect is designing an access management solution for a new internal web application. The application will be accessed by employees using various devices, including corporate-managed laptops and personal mobile phones. The architect needs to ensure that access to the application from corporate-managed devices requires only a single sign-on (SSO) experience, while access from personal mobile phones requires MFA and is restricted to specific trusted network locations. Which combination of Azure AD features should the architect implement?
- AAzure AD Seamless SSO and Conditional Access policies.
- BAzure AD Application proxy and Azure AD Identity Protection.
- CPassword Hash Synchronization and PIM.
- DAzure AD B2B collaboration and Conditional Access policies.
Show answer & explanationAnswer & explanation
Correct answer: A. Azure AD Seamless SSO and Conditional Access policies.
Azure AD Seamless SSO provides a true single sign-on experience for users on corporate-managed, domain-joined devices. Conditional Access policies are then used to enforce the specific requirements, such as requiring MFA and trusted locations for personal mobile phones, and potentially allowing a more seamless experience for managed devices.
Why the other options are wrong
- B. Azure AD Application proxy is for publishing on-premises applications, and Identity Protection is for risk-based policies, neither directly addresses the core SSO requirement for corporate devices combined with granular device/location access controls.
- C. Password Hash Synchronization is an authentication method, and PIM is for privileged access management, neither directly addresses the SSO experience or granular access controls based on device/location.
- D. Azure AD B2B is for external users, not internal employees, and doesn't directly provide SSO for domain-joined devices.
Azure AD Seamless SSO + Conditional Access
Azure AD Seamless Single Sign-On (SSO) provides users with an automatic sign-in experience when their corporate devices are within the corporate network. Conditional Access policies then layer on top to enforce specific access controls (like MFA, trusted locations, compliant devices) based on user, device, location, and application.
- Seamless SSO works with PHS or PTA authentication methods.
- Conditional Access allows granular control over access based on various signals.
- Combining them provides both user experience and strong security.
Memory trick: Seamless SSO for managed, Conditional Access for control.