Microsoft Certified: Azure Security Engineer AssociateManage identity and accessEasy

A financial services company uses Azure AD and has deployed several mission-critical applications. They need to ensure that access to these applications is only granted from devices that are compliant with their security policies (e.g., up-to-date antivirus, encrypted hard drive). Which Azure AD feature should be used to enforce this device compliance requirement?

  1. AAzure AD Multi-Factor Authentication (MFA)
  2. BAzure AD Identity Protection
  3. CAzure AD Conditional Access
  4. DAzure AD Privileged Identity Management (PIM)
Show answer & explanation

Correct answer: C. Azure AD Conditional Access

Azure AD Conditional Access allows organizations to enforce policies based on specific conditions, including device state. By integrating with Microsoft Intune (or a third-party MDM), Conditional Access can verify if a device is compliant with organizational policies before granting access to resources.

Why the other options are wrong

  • A. MFA verifies user identity, not the security posture of the device being used.
  • B. Identity Protection focuses on detecting and remediating identity-based risks, not device compliance.
  • D. PIM manages just-in-time access for privileged roles, not device compliance.

Azure AD Conditional Access

A policy-based access control engine that evaluates conditions and enforces security requirements before granting access to resources.

  • Granular access control based on user, device, location, app.
  • Requires Azure AD Premium P1.
  • Integrates with MDM for device compliance.

Memory trick: Conditional Access: Conditions Control Access.

More Manage identity and access questions