Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureHard

A global healthcare provider is designing a Zero Trust architecture for its patient data systems, which are hosted across Azure and an on-premises data center. The organization needs to ensure that data access policies are consistently applied, audited, and enforced, regardless of where the data resides or how it is accessed. Which Azure service is BEST suited to provide a centralized and consistent policy engine for this hybrid environment?

  1. AAzure Front Door
  2. BAzure Information Protection
  3. CAzure Policy
  4. DAzure Active Directory Conditional Access
Show answer & explanation

Correct answer: D. Azure Active Directory Conditional Access

Azure Active Directory Conditional Access is specifically designed to enforce access policies based on various conditions such as user, device, location, and application, both for cloud and hybrid resources integrated with Azure AD. It provides a centralized policy engine that can adapt to the Zero Trust principle of 'Verify Explicitly' across diverse environments.

Why the other options are wrong

  • A. Azure Front Door is primarily a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications. It does not provide a centralized policy engine for data access.
  • B. Azure Information Protection (AIP) helps classify, label, and protect documents and emails. It's about data protection, not the centralized enforcement of real-time access policies based on user and device context.
  • C. Azure Policy helps to enforce organizational standards and assess compliance at scale for Azure resources. While it enforces policies, its primary focus is on resource configuration and compliance within Azure, not dynamic access decisions based on user/device context across hybrid environments.

Azure AD Conditional Access

A feature of Azure Active Directory that enables organizations to enforce policies to control access to resources based on specific conditions.

  • Centralized policy enforcement.
  • Evaluates conditions like user, device, location, application, and sign-in risk.
  • Supports both cloud and hybrid resources integrated with Azure AD.

Memory trick: Conditional Access is the Central Gatekeeper for Hybrid Resources.

More Design a Zero Trust strategy and architecture questions