Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureHard

A research institution is designing a Zero Trust strategy for its highly confidential scientific data stored in Azure Blob Storage. The institution requires that access to this data is not only based on user identity and role but also dynamically re-evaluated based on real-time factors like the user's location, device compliance, and even the sensitivity of the specific data being accessed. If any of these factors change during a session, access should be immediately revoked or restricted. Which Azure AD feature is crucial for implementing this dynamic, continuous access evaluation?

  1. AAzure AD Access Reviews
  2. BAzure AD Identity Protection
  3. CContinuous Access Evaluation (CAE)
  4. DAzure AD Privileged Identity Management (PIM)
Show answer & explanation

Correct answer: C. Continuous Access Evaluation (CAE)

Continuous Access Evaluation (CAE) in Azure AD allows for real-time enforcement of Conditional Access policies. Instead of waiting for token expiration, CAE enables immediate revocation of access tokens when critical events occur, such as a user's location change, device non-compliance, or a high-risk sign-in, directly addressing the need for dynamic, real-time re-evaluation and revocation.

Why the other options are wrong

  • A. Azure AD Access Reviews help manage group memberships and application access by periodically reviewing who has access to what, which is a periodic governance control, not a real-time, dynamic access evaluation mechanism.
  • B. Azure AD Identity Protection detects and remediates identity-based risks, feeding into Conditional Access policies, but CAE is the mechanism for continuous, real-time policy enforcement and token revocation.
  • D. Azure AD PIM manages just-in-time and just-enough access for privileged roles, but it does not provide real-time, dynamic re-evaluation of access during an active session based on changing conditions.

Continuous Access Evaluation (CAE)

An Azure AD feature that enables real-time enforcement of Conditional Access policies by allowing immediate revocation of access tokens upon detecting critical events.

  • Real-time access policy enforcement.
  • Revokes tokens immediately, not waiting for expiration.
  • Responds to critical events like location change, device non-compliance, or risk increase.

Memory trick: CAE constantly checks, revoking access if conditions change.

More Design a Zero Trust strategy and architecture questions