nerdexam
Microsoft

SC-100 · Question #235

You have on-premises Windows 11 devices that have the Global Secure Access client deployed. You have a Microsoft 365 subscription that uses Microsoft SharePoint Online and Exchange Online. You…

The correct answer is A. SharePoint Online only. Compliant network enforcement reduces the risk of token theft/replay attacks. Compliant network enforcement happens at the authentication plane (generally available) and at the data plane (preview). Authentication plane enforcement is performed by Microsoft Entra ID at the time…

Design security operations, identity, and compliance capabilities

Question

You have on-premises Windows 11 devices that have the Global Secure Access client deployed. You have a Microsoft 365 subscription that uses Microsoft SharePoint Online and Exchange Online. You deploy Microsoft Entra Internet Access from the on-premises network to Microsoft 365. The deployment has the Microsoft 365 profile enabled and contains the following:

  • Default traffic policies for Microsoft 365 services
  • A linked Conditional Access policy that performs compliant network

checks with continuous access evaluation and is applied to all users

  • An assignment to all the devices
  • An assignment to a remote network associated with the on-premises

network Which Microsoft 365 resources are protected by using continuous access evaluation?

Options

  • ASharePoint Online only
  • BExchange Online only
  • Cboth SharePoint Online and Exchange Online

How the community answered

(32 responses)
  • A
    72% (23)
  • B
    19% (6)
  • C
    9% (3)

Explanation

Compliant network enforcement reduces the risk of token theft/replay attacks. Compliant network enforcement happens at the authentication plane (generally available) and at the data plane (preview). Authentication plane enforcement is performed by Microsoft Entra ID at the time of user authentication. If an adversary has stolen a session token and attempts to replay it from a device that is not connected to your organization's compliant network (for example, requesting an access token with a stolen refresh token), Entra ID will immediately deny the request and further access will be blocked. Data plane enforcement works with services that support Continuous Access Evaluation (CAE) - currently, only SharePoint Online. With apps that support CAE, stolen access tokens that are replayed outside your tenant's compliant network will be rejected by the application in near-real time. Without CAE, a stolen access token will last up to its full lifetime (default 60-90 minutes). https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-compliant-network

Topics

#Continuous Access Evaluation#Microsoft Entra Internet Access#Conditional Access#Microsoft 365 Security

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice