Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard

A company is utilizing Azure AD to manage user identities. They have a critical business application that needs to be accessible only by users who are part of a specific security group, and only from corporate-managed devices. Furthermore, access should be blocked if any sign-in risk is detected for the user. Which combination of Azure AD features should be configured to enforce these granular access controls?

  1. AAzure AD Connect and Azure AD Privileged Identity Management
  2. BAzure AD B2B collaboration and Azure AD Conditional Access
  3. CAzure AD Conditional Access and Azure AD Identity Protection
  4. DAzure AD PIM and Azure AD Identity Protection
Show answer & explanation

Correct answer: C. Azure AD Conditional Access and Azure AD Identity Protection

Azure AD Conditional Access allows defining policies based on user groups and device state (corporate-managed). Azure AD Identity Protection integrates with Conditional Access to block access based on detected sign-in risks, fulfilling all requirements.

Why the other options are wrong

  • A. Azure AD Connect synchronizes identities, and PIM manages privileged access. Neither addresses device state or sign-in risk for general access policies.
  • B. B2B collaboration is for external users; it doesn't address corporate-managed devices or sign-in risk for internal users.
  • D. PIM manages privileged access, not general user access based on device state or sign-in risk.

Conditional Access + Identity Protection

A powerful combination in Azure AD where Conditional Access policies are enhanced by real-time risk detections from Identity Protection to enforce adaptive access controls.

  • Conditional Access defines 'if-then' access rules.
  • Identity Protection feeds sign-in and user risk levels into Conditional Access.
  • Allows for highly adaptive and dynamic access policies based on risk and context.

Memory trick: Smart access: know who, from where, and how risky.

More Manage identity and access questions