AZ-305 · Question #2
Case Study 1 - Litware Existing Environment Azure Environment Litware has 10 Azure subscriptions that are linked to the Litware.com tenant and five Azure subscriptions that are linked to the…
This hotspot question tests knowledge of Azure AD Conditional Access policies, hybrid Azure AD join requirements, and role assignment scopes within a multi-tenant, Enterprise Agreement environment at Litware.
Question
Exhibits
Answer Area
- Database:A single Azure SQL databaseAzure SQL Managed InstanceAn Azure SQL Database elastic pool
- Service tier:HyperscaleBusiness CriticalGeneral Purpose
Explanation
This hotspot question tests knowledge of Azure AD Conditional Access policies, hybrid Azure AD join requirements, and role assignment scopes within a multi-tenant, Enterprise Agreement environment at Litware.
Approach. The requirement states that only users managing the production environment via the Azure portal must connect from a hybrid Azure AD-joined device and use multi-factor authentication (MFA). This is implemented through an Azure AD Conditional Access policy targeting the specific users/roles accessing production subscriptions, with conditions requiring a compliant/hybrid Azure AD-joined device and MFA grant controls. Role1, which grants DataActions read on blobs and files, is a custom Azure RBAC role defined at the litware.com tenant level and can be assigned within any subscription linked to that tenant but cannot be directly used in the dev.litware.com tenant subscriptions since custom roles are tenant-scoped. Dedicated hosts for App1 VMs must be planned at the subscription level where the VMs will reside, and ExpressRoute connectivity already provides the hybrid network path needed for on-premises workloads migrating to Azure.
Concept tested. Azure AD Conditional Access policies for hybrid Azure AD-joined device requirements, custom Azure RBAC role tenant scoping, and planning Azure dedicated hosts and ExpressRoute-connected hybrid environments for workload migration.
Reference. https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/overview | https://learn.microsoft.com/en-us/azure/role-based-access-control/custom-roles | https://learn.microsoft.com/en-us/azure/virtual-machines/dedicated-hosts
Topics
Community Discussion
No community discussion yet for this question.

