Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingMedium

A company is using Azure Active Directory (Azure AD) for identity and access management. They want to ensure that users accessing sensitive applications from untrusted locations or non-compliant devices are prompted for multi-factor authentication (MFA) or blocked entirely. Which Azure AD feature can enforce these types of access policies?

  1. AAzure AD B2B collaboration
  2. BAzure AD Identity Protection
  3. CAzure AD Privileged Identity Management (PIM)
  4. DAzure AD Conditional Access
Show answer & explanation

Correct answer: D. Azure AD Conditional Access

Azure AD Conditional Access is the tool used by Azure Active Directory to bring signals together, make decisions, and enforce organizational policies. It allows you to create 'if-then' statements, such as 'if a user is accessing a sensitive application from an untrusted location, then require MFA'.

Why the other options are wrong

  • A. Azure AD B2B collaboration allows you to securely share your applications and services with external guest users.
  • B. Azure AD Identity Protection detects and remediates identity-based risks.
  • C. Azure AD PIM manages, controls, and monitors access to important resources in Azure AD.

Azure AD Conditional Access

Azure AD Conditional Access is a feature that enables you to enforce policies based on conditions such as user, location, device state, and application, to control access to resources.

  • Enforces 'if-then' policies
  • Uses signals like user, device, location, application
  • Can require MFA, block access, or only allow access from specific devices
  • Key component of Zero Trust security model

Memory trick: Conditional Access is your smart bouncer for apps, checking conditions before letting anyone in.

More Describe Azure identity, security, and networking questions