Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingMedium

A company is implementing a zero-trust security model in Azure. They need to ensure that access to resources is granted only after explicit verification of the user, device, and environment. Which Azure security feature directly supports this principle by evaluating conditions before granting access?

  1. AAzure Key Vault
  2. BAzure Conditional Access
  3. CAzure Sentinel
  4. DAzure Security Center
Show answer & explanation

Correct answer: B. Azure Conditional Access

Azure Conditional Access is a feature of Azure Active Directory that evaluates conditions such as user, location, device, and application to make real-time access decisions, directly supporting a zero-trust model.

Why the other options are wrong

  • A. Azure Key Vault securely stores cryptographic keys and secrets, not for evaluating access conditions.
  • C. Azure Sentinel is a cloud-native SIEM (Security Information and Event Management) for security analytics, not for enforcing access policies.
  • D. Azure Security Center (now Defender for Cloud) provides cloud security posture management and threat protection, but doesn't enforce access policies directly.

Azure Conditional Access

A feature of Azure AD that enables organizations to enforce policies based on conditions to control access to resources.

  • Evaluates user, device, location, and application conditions.
  • Supports a zero-trust security model.
  • Can require MFA, block access, or restrict access.

Memory trick: Trust 'no one' implicitly, 'verify' everything 'conditionally'.

More Describe Azure identity, security, and networking questions