Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureHard

A healthcare provider is designing a Zero Trust architecture for its patient data systems, which are hosted in a hybrid environment (on-premises and Azure). They need to ensure that access to sensitive patient records is continuously evaluated and re-authorized, even after an initial access decision has been made. If a user's risk profile changes (e.g., due to a sign-in from an unusual location) or a device becomes non-compliant during an active session, access must be immediately revoked without waiting for the session to expire. This is critical for maintaining compliance with strict healthcare regulations.

  1. AImplement Azure AD Conditional Access policies with Continuous Access Evaluation (CAE).
  2. BRequire multi-factor authentication (MFA) for every single access request to patient data.
  3. CConfigure session timeouts for all applications accessing patient data to a very short duration.
  4. DDeploy a dedicated intrusion prevention system (IPS) to block suspicious network traffic.
Show answer & explanation

Correct answer: A. Implement Azure AD Conditional Access policies with Continuous Access Evaluation (CAE).

Continuous Access Evaluation (CAE) in Azure AD Conditional Access is specifically designed to address this requirement. It allows for near real-time revocation of access tokens when critical events occur, such as a user's location changing, a device becoming non-compliant, or a user's risk profile increasing, without waiting for the standard token expiration, thus ensuring continuous re-authorization.

Why the other options are wrong

  • B. While MFA is crucial for initial authentication, requiring it for every single request would be highly disruptive and does not address the need for continuous evaluation and revocation during an active session.
  • C. Short session timeouts can be disruptive to user experience and may not immediately revoke access upon a critical event, as the session might still be active for a few minutes.
  • D. An IPS primarily blocks network-level threats and does not directly manage or revoke active user sessions based on identity or device compliance changes.

Continuous Access Evaluation (CAE)

A feature in Azure AD Conditional Access that allows for near real-time enforcement of access policies by immediately revoking access tokens upon critical events.

  • Revokes access tokens immediately upon critical events (e.g., user risk change, device non-compliance).
  • Enhances security by enforcing policies continuously during active sessions.
  • Reduces the window of opportunity for attackers.
  • Works with applications that support CAE-aware clients (e.g., Microsoft 365 apps).

Memory trick: CAE: Continuously Assess Everything.

More Design a Zero Trust strategy and architecture questions