Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureMedium

A company is adopting a Zero Trust model and needs to ensure that all devices accessing corporate resources, whether corporate-owned or personal (BYOD), meet specific security standards before being granted access. This includes checking for up-to-date antivirus definitions, operating system patches, and disk encryption. The security architect must integrate this device posture assessment into the access decision process. Which component of a Zero Trust architecture is responsible for evaluating and reporting device health and compliance?

  1. ADevice Management Solution (e.g., MDM/UEM)
  2. BPolicy Decision Point (PDP)
  3. CPolicy Enforcement Point (PEP)
  4. DIdentity Provider (IdP)
Show answer & explanation

Correct answer: A. Device Management Solution (e.g., MDM/UEM)

The scenario specifically describes the need to assess device health and compliance (antivirus, patches, encryption). A Device Management Solution (like MDM or UEM) is responsible for monitoring, managing, and reporting on the security posture of devices, integrating this data into the Zero Trust decision-making process.

Why the other options are wrong

  • B. The Policy Decision Point makes the access decision based on various inputs, including device health, but doesn't collect the health data.
  • C. The Policy Enforcement Point enforces the access decision but doesn't evaluate device health itself.
  • D. The Identity Provider authenticates users but doesn't primarily assess device health.

Device Management Solution (Zero Trust)

A system (e.g., MDM, UEM) responsible for monitoring, managing, and enforcing security policies on endpoints, providing critical device health and compliance data for Zero Trust access decisions.

  • Collects device posture information (OS version, patches, AV status).
  • Enrolls and manages corporate and personal devices.
  • Integrates with Policy Decision Points to inform access grants.

Memory trick: IdP Authenticates, Device Manages, PDP Decides, PEP Enforces.

More Design a Zero Trust strategy and architecture questions