A research institution is designing a Zero Trust strategy for its highly confidential scientific data. The data is stored in Azure Blob Storage and accessed by researchers from various locations. The institution requires that access to this data is not only authenticated but also continuously re-evaluated based on changes in user behavior, device posture, and potential environmental risks, even during an active session. Which Zero Trust concept does this continuous re-evaluation during a session primarily represent?
- AJust-In-Time (JIT) access
- BIdentity Governance
- CStatic access review
- DDynamic access policies
Show answer & explanationAnswer & explanation
Correct answer: D. Dynamic access policies
Dynamic access policies (often implemented via Continuous Access Evaluation in Azure AD) enable the continuous re-evaluation of access during an active session based on real-time signals, such as changes in user location, device compliance, or detected risk events. This goes beyond initial authentication and ensures that trust is never implicit, aligning with advanced Zero Trust principles.
Why the other options are wrong
- A. Just-In-Time (JIT) access grants elevated permissions for a limited time, but doesn't inherently imply continuous re-evaluation of an active session for changes in risk.
- B. Identity Governance focuses on managing the identity lifecycle, access requests, and access reviews, which are typically periodic, not continuous re-evaluation during a session.
- C. Static access review involves periodic checks of access rights, not continuous, real-time re-evaluation during an active session.
Dynamic Access Policies (Continuous Access Evaluation)
A Zero Trust mechanism that enables the continuous re-evaluation of access during an active session based on real-time signals, such as changes in user location, device posture, or detected risk events. It ensures that trust is never implicit and access can be revoked immediately if risk conditions change.
- Continuous re-evaluation during active session
- Based on real-time signals
- Revokes access immediately if risk changes
- Never implicit trust
Memory trick: Access is a constantly moving target, always re-checked.