Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureEasy
A multinational corporation is designing a Zero Trust architecture for its global operations. The security team wants to ensure that all user identities, whether employees or external partners, are subject to the same rigorous authentication and authorization policies, regardless of their origin. What identity-centric Zero Trust control should be prioritized to achieve this goal?
- AConditional Access Policies
- BJust-In-Time (JIT) Access
- CDevice Compliance Policies
- DMulti-Factor Authentication (MFA)
Show answer & explanationAnswer & explanation
Correct answer: A. Conditional Access Policies
Conditional Access Policies allow organizations to enforce specific authentication and authorization requirements, such as MFA, device compliance, or location restrictions, based on various conditions, ensuring consistent policy application for all identities.
Why the other options are wrong
- B. Just-In-Time (JIT) Access is a least privilege principle for elevated roles, not the main mechanism for applying consistent policies across all identities.
- C. Device Compliance Policies ensure devices meet security standards, which is a component of Conditional Access, but not the overarching control for identity-centric policies.
- D. Multi-Factor Authentication (MFA) is a specific authentication method, often enforced by Conditional Access, but not the comprehensive policy framework itself.
Conditional Access Policies
Azure AD Conditional Access policies are if-then statements: if a user wants to access a resource, then they must complete an action. These policies enable organizations to enforce specific authentication and authorization requirements based on various conditions, such as user location, device state, or application being accessed.
- If-then statements for access
- Enforce specific requirements based on conditions
- Granular control over access
- Integrates with MFA, device compliance, etc.
Memory trick: Conditions dictate who gets access and how.