Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard
A company is utilizing Azure AD to manage user identities. They have a critical business application that needs to be accessible only by users who are part of a specific security group, and only from corporate-managed devices. Furthermore, access should be blocked if any sign-in risk is detected for the user. Which combination of Azure AD features should be configured to enforce these granular access controls?
- AAzure AD Connect and Azure AD Privileged Identity Management
- BAzure AD B2B collaboration and Azure AD Conditional Access
- CAzure AD Conditional Access and Azure AD Identity Protection
- DAzure AD PIM and Azure AD Identity Protection
Show answer & explanationAnswer & explanation
Correct answer: C. Azure AD Conditional Access and Azure AD Identity Protection
Azure AD Conditional Access allows defining policies based on user groups and device state (corporate-managed). Azure AD Identity Protection integrates with Conditional Access to block access based on detected sign-in risks, fulfilling all requirements.
Why the other options are wrong
- A. Azure AD Connect synchronizes identities, and PIM manages privileged access. Neither addresses device state or sign-in risk for general access policies.
- B. B2B collaboration is for external users; it doesn't address corporate-managed devices or sign-in risk for internal users.
- D. PIM manages privileged access, not general user access based on device state or sign-in risk.
Conditional Access + Identity Protection
A powerful combination in Azure AD where Conditional Access policies are enhanced by real-time risk detections from Identity Protection to enforce adaptive access controls.
- Conditional Access defines 'if-then' access rules.
- Identity Protection feeds sign-in and user risk levels into Conditional Access.
- Allows for highly adaptive and dynamic access policies based on risk and context.
Memory trick: Smart access: know who, from where, and how risky.