SC-100 · Question #235
You have on-premises Windows 11 devices that have the Global Secure Access client deployed. You have a Microsoft 365 subscription that uses Microsoft SharePoint Online and Exchange Online. You…
The correct answer is A. SharePoint Online only. Compliant network enforcement reduces the risk of token theft/replay attacks. Compliant network enforcement happens at the authentication plane (generally available) and at the data plane (preview). Authentication plane enforcement is performed by Microsoft Entra ID at the time…
Question
You have on-premises Windows 11 devices that have the Global Secure Access client deployed. You have a Microsoft 365 subscription that uses Microsoft SharePoint Online and Exchange Online. You deploy Microsoft Entra Internet Access from the on-premises network to Microsoft 365. The deployment has the Microsoft 365 profile enabled and contains the following:
- Default traffic policies for Microsoft 365 services
- A linked Conditional Access policy that performs compliant network
checks with continuous access evaluation and is applied to all users
- An assignment to all the devices
- An assignment to a remote network associated with the on-premises
network Which Microsoft 365 resources are protected by using continuous access evaluation?
Options
- ASharePoint Online only
- BExchange Online only
- Cboth SharePoint Online and Exchange Online
How the community answered
(32 responses)- A72% (23)
- B19% (6)
- C9% (3)
Explanation
Compliant network enforcement reduces the risk of token theft/replay attacks. Compliant network enforcement happens at the authentication plane (generally available) and at the data plane (preview). Authentication plane enforcement is performed by Microsoft Entra ID at the time of user authentication. If an adversary has stolen a session token and attempts to replay it from a device that is not connected to your organization's compliant network (for example, requesting an access token with a stolen refresh token), Entra ID will immediately deny the request and further access will be blocked. Data plane enforcement works with services that support Continuous Access Evaluation (CAE) - currently, only SharePoint Online. With apps that support CAE, stolen access tokens that are replayed outside your tenant's compliant network will be rejected by the application in near-real time. Without CAE, a stolen access token will last up to its full lifetime (default 60-90 minutes). https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-compliant-network
Topics
Community Discussion
No community discussion yet for this question.