Microsoft 365 FundamentalsDescribe security, compliance, privacy, and trust in Microsoft 365Hard
A Microsoft 365 administrator is implementing a new policy to ensure that users access Microsoft 365 services only from devices that are compliant with corporate security standards (e.g., up-to-date antivirus, device encryption enabled). If a device is not compliant, access should be blocked or require multi-factor authentication. Which Azure AD capability provides this granular access control?
- AAzure AD Security Defaults
- BAzure AD Conditional Access
- CMicrosoft Entra Verified ID
- DAzure AD Identity Protection
Show answer & explanationAnswer & explanation
Correct answer: B. Azure AD Conditional Access
Azure AD Conditional Access allows administrators to define policies that enforce specific access requirements based on conditions such as user, location, device state (compliant or not), and application. This enables granular control over who can access resources and under what circumstances.
Why the other options are wrong
- A. Security Defaults provide a baseline, but not the granular, custom control needed for device compliance.
- C. Verified ID is for decentralized identity and verifiable credentials, not for enforcing device compliance for existing Azure AD users.
- D. Identity Protection detects risks, but Conditional Access is the policy engine that enforces actions based on those risks or other conditions.
Azure AD Conditional Access
An Azure Active Directory feature that enables organizations to enforce policies that evaluate conditions (such as user group, location, device state, application) and then enforce specific access controls (like MFA, blocking access, or requiring a compliant device) in real-time.
- Enforces policies based on conditions.
- Allows granular control over access to resources.
- Integrates with Intune for device compliance.
Memory trick: Conditional Access: Only if the light is green and your car is safe, can you pass.