Microsoft Certified: Azure Security Engineer AssociateManage identity and accessEasy
A financial services company uses Azure AD and has deployed several mission-critical applications. They need to ensure that access to these applications is only granted from devices that are compliant with their security policies (e.g., up-to-date antivirus, encrypted hard drive). Which Azure AD feature should be used to enforce this device compliance requirement?
- AAzure AD Multi-Factor Authentication (MFA)
- BAzure AD Identity Protection
- CAzure AD Conditional Access
- DAzure AD Privileged Identity Management (PIM)
Show answer & explanationAnswer & explanation
Correct answer: C. Azure AD Conditional Access
Azure AD Conditional Access allows organizations to enforce policies based on specific conditions, including device state. By integrating with Microsoft Intune (or a third-party MDM), Conditional Access can verify if a device is compliant with organizational policies before granting access to resources.
Why the other options are wrong
- A. MFA verifies user identity, not the security posture of the device being used.
- B. Identity Protection focuses on detecting and remediating identity-based risks, not device compliance.
- D. PIM manages just-in-time access for privileged roles, not device compliance.
Azure AD Conditional Access
A policy-based access control engine that evaluates conditions and enforces security requirements before granting access to resources.
- Granular access control based on user, device, location, app.
- Requires Azure AD Premium P1.
- Integrates with MDM for device compliance.
Memory trick: Conditional Access: Conditions Control Access.