Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium
A software development company uses Azure AD to manage access for its developers. They want to ensure that developers can only access specific source code repositories from devices that are marked as 'compliant' by Microsoft Intune. If a device is non-compliant, access should be blocked. Which type of Conditional Access policy should be configured?
- ALocation-based policy
- BUser risk-based policy
- CDevice state-based policy
- DSign-in risk-based policy
Show answer & explanationAnswer & explanation
Correct answer: C. Device state-based policy
A device state-based Conditional Access policy allows you to enforce access controls based on whether a device is marked as 'compliant' or 'hybrid Azure AD joined'. This directly addresses the requirement to block access from non-compliant devices.
Why the other options are wrong
- A. Location-based policies restrict access based on network location (e.g., trusted IPs), not device compliance.
- B. User risk-based policies block or challenge users based on their historical risk level, not device compliance.
- D. Sign-in risk-based policies block or challenge based on the risk associated with a specific sign-in attempt, not device compliance.
Conditional Access Device State
A condition in Azure AD Conditional Access policies that allows evaluating the compliance or join state of a device to control access to resources.
- Integrates with Microsoft Intune for device compliance.
- Can block access from non-compliant devices.
- Supports 'Hybrid Azure AD joined' and 'Azure AD joined' devices.
Memory trick: Device state is like a bouncer checking your ID and vaccination card.