SC-100 · Question #161
You have a Microsoft 365 subscription. You need to design a solution to block file downloads from Microsoft SharePoint Online by authenticated users on unmanaged devices. Which two services should…
The correct answer is A. Azure AD Conditional Access E. Microsoft Defender for Cloud Apps. Blocking SharePoint Online file downloads from unmanaged devices requires two components working together. Azure AD Conditional Access (A) identifies whether the device accessing SharePoint Online is managed or unmanaged (using device compliance or hybrid Azure AD join signals)…
Question
You have a Microsoft 365 subscription. You need to design a solution to block file downloads from Microsoft SharePoint Online by authenticated users on unmanaged devices. Which two services should you include in the solution? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Options
- AAzure AD Conditional Access
- BAzure Data Catalog
- CMicrosoft Purview Information Protection
- DAzure AD Application Proxy
- EMicrosoft Defender for Cloud Apps
How the community answered
(28 responses)- A82% (23)
- B4% (1)
- C11% (3)
- D4% (1)
Explanation
Blocking SharePoint Online file downloads from unmanaged devices requires two components working together. Azure AD Conditional Access (A) identifies whether the device accessing SharePoint Online is managed or unmanaged (using device compliance or hybrid Azure AD join signals) and can route the session through a Conditional Access App Control policy. Microsoft Defender for Cloud Apps (E) acts as the enforcement engine: it integrates with Conditional Access as a reverse proxy and applies session policies that specifically block download actions in SharePoint Online for sessions originating from unmanaged devices. Azure Data Catalog (B) is a data discovery/governance service with no session control capability. Microsoft Purview Information Protection (C) applies sensitivity labels and encryption to documents but does not block download actions at the session level. Azure AD Application Proxy (D) is for publishing on-premises apps externally and is not involved in controlling SharePoint Online sessions.
Topics
Community Discussion
No community discussion yet for this question.