Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureHard

A large pharmaceutical company is implementing a Zero Trust strategy. They have a complex environment with numerous applications, some of which are legacy and lack modern authentication protocols. The security architect needs to ensure that all access to these legacy applications is protected by multi-factor authentication (MFA) and Conditional Access policies, even though the applications themselves cannot directly integrate with Azure AD. Which component of a Zero Trust architecture acts as an intermediary to enforce these modern security controls for legacy applications?

  1. AAzure AD Connect
  2. BIdentity Provider (IdP)
  3. CPolicy Enforcement Point (PEP)
  4. DSecurity Assertion Markup Language (SAML)
Show answer & explanation

Correct answer: C. Policy Enforcement Point (PEP)

The scenario describes enforcing MFA and Conditional Access for legacy apps that cannot directly integrate with Azure AD. A Policy Enforcement Point (PEP) acts as the intermediary (e.g., an application proxy, a network access control solution, or a reverse proxy) that intercepts access requests, interacts with the Policy Decision Point (PDP) for authorization, and then enforces the decision (e.g., requiring MFA) before passing the request to the legacy application.

Why the other options are wrong

  • A. Azure AD Connect synchronizes identities but doesn't enforce access policies for applications.
  • B. The Identity Provider (IdP) authenticates the user, but a separate component is needed to *enforce* policies like MFA for a legacy application that doesn't natively support it.
  • D. SAML is an XML-based standard for exchanging authentication and authorization data, a protocol, not a component that enforces policies for legacy apps.

Policy Enforcement Point (PEP)

A component in a Zero Trust architecture responsible for granting, denying, or revoking access to a resource based on the authorization decision from a Policy Decision Point (PDP), often acting as a gatekeeper for applications.

  • Intercepts access requests.
  • Communicates with the PDP for authorization.
  • Enforces policies like MFA or Conditional Access, especially for legacy apps.

Memory trick: PEP Enforces Policies at the Gate.

More Design a Zero Trust strategy and architecture questions