Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium
A global manufacturing company uses Azure AD for identity management. Due to recent security audits, they need to implement a solution that prevents users from accessing sensitive applications from untrusted devices or locations. This solution must also enforce multi-factor authentication (MFA) when users attempt to access these applications from outside the corporate network. Which Azure AD feature is best suited to meet these requirements?
- AAzure AD Identity Protection
- BAzure AD B2B collaboration
- CAzure AD Conditional Access
- DAzure AD Privileged Identity Management
Show answer & explanationAnswer & explanation
Correct answer: C. Azure AD Conditional Access
Azure AD Conditional Access allows organizations to enforce policies based on user, device, location, and application conditions, enabling granular control over access to resources.
Why the other options are wrong
- A. Azure AD Identity Protection detects and remediates identity-based risks, but doesn't directly enforce access policies based on conditions.
- B. Azure AD B2B collaboration manages external user access, but doesn't provide conditional access enforcement for internal users.
- D. Azure AD Privileged Identity Management (PIM) manages, controls, and monitors access to important resources, primarily for privileged roles, not general user access conditions.
Azure AD Conditional Access
A feature of Azure Active Directory that allows organizations to enforce policies based on specific conditions to control access to resources.
- Uses 'if-then' statements to define policies.
- Conditions include user/group, cloud apps, device platform, location, client apps, and device state.
- Access controls include block access, require MFA, require compliant devices, etc.
Memory trick: Conditions dictate access, like a traffic light for your apps.