Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureMedium

A global enterprise is designing its Zero Trust architecture and needs to ensure that all devices accessing corporate resources, whether corporate-owned or personal (BYOD), meet specific security standards before being granted access. This includes checking for up-to-date antivirus, operating system patches, and disk encryption. Which type of solution is essential for implementing this control?

  1. AIdentity Governance and Administration (IGA)
  2. BData Loss Prevention (DLP)
  3. CDevice Management Solution (e.g., MDM/MAM)
  4. DSecurity Information and Event Management (SIEM)
Show answer & explanation

Correct answer: C. Device Management Solution (e.g., MDM/MAM)

A Device Management Solution, such as Mobile Device Management (MDM) or Mobile Application Management (MAM), is essential for assessing and enforcing device compliance. These solutions can check device health, configuration, and security posture, and then report this information to Conditional Access policies to grant or deny access based on Zero Trust principles.

Why the other options are wrong

  • A. IGA manages user identities and access rights, not the security posture of devices.
  • B. DLP prevents data exfiltration but doesn't manage device security posture.
  • D. SIEM collects logs for threat detection, not for enforcing device compliance.

Device Management Solution (Zero Trust)

A system (e.g., MDM, MAM) used to manage and secure devices accessing corporate resources, ensuring they meet defined security standards and compliance policies.

  • Assesses device health (antivirus, patches, encryption).
  • Enforces security configurations.
  • Integrates with Conditional Access for policy-based access decisions.
  • Crucial for securing endpoints in a Zero Trust model.

Memory trick: Devices must be 'Managed' to be 'Trusted'.

More Design a Zero Trust strategy and architecture questions