Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingHard

A company is implementing a zero-trust security model. They need to ensure that users accessing sensitive applications in Azure must re-authenticate and provide a second factor of authentication if they are connecting from an untrusted network location or a non-compliant device. Which Azure AD feature provides this capability?

  1. AAzure AD Conditional Access
  2. BAzure MFA
  3. CAzure AD Identity Protection
  4. DAzure AD Privileged Identity Management (PIM)
Show answer & explanation

Correct answer: A. Azure AD Conditional Access

Azure AD Conditional Access enables organizations to enforce policies based on specific conditions, such as user location, device compliance, and application being accessed. It can require actions like multi-factor authentication (MFA) or device compliance for access under certain conditions, aligning with a zero-trust model.

Why the other options are wrong

  • B. Azure MFA provides multi-factor authentication, but Conditional Access is the engine that determines *when* MFA is required based on conditions.
  • C. Azure AD Identity Protection identifies and remediates identity-based risks, but Conditional Access applies the specific access policies.
  • D. Azure AD PIM manages, controls, and monitors access to important resources, usually for privileged roles, not general user access conditions.

Azure AD Conditional Access

A feature of Azure Active Directory that enables organizations to enforce policies based on specific conditions to control access to resources.

  • Combines signals like user, device, location, and application.
  • Enforces decisions like requiring MFA, blocking access, or requiring a compliant device.
  • Central to implementing a zero-trust security model.

Memory trick: Conditional Access grants access, but only if the conditions are right.

More Describe Azure identity, security, and networking questions