SC-100 · Question #242
Your company has a main office and a branch office. The main office contains 20 on-premises servers that run Windows Server and host apps that are published by using Microsoft Entra application…
The correct answer is A. connections to the third-party SaaS app C. Continuous Access Evaluation for Microsoft Exchange Online. Global Secure Access compliant network check integrates with Conditional Access to verify traffic routes through the Global Secure Access service. A is correct because third-party SaaS apps registered in the Microsoft Entra tenant can be protected with Conditional Access…
Question
Your company has a main office and a branch office. The main office contains 20 on-premises servers that run Windows Server and host apps that are published by using Microsoft Entra application proxy. The main office contains 500 on-premises computers that run Windows 11. The branch office contains 100 on-premises computers that run Windows 11. NOT enrolled in Intune. All the main office computers are enrolled in Microsoft Intune. The branch office computers are You have a Microsoft 365 ES subscription. You have a Microsoft Entra tenant. You have a third-party software as a service (SaaS) app that is registered in the Microsoft Entra tenant. You plan to implement Global Secure Access. You are evaluating the use of compliant network check and Conditional Access. Which two scenarios are supported by compliant network check? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point
Options
- Aconnections to the third-party SaaS app
- Bconnections from the branch office computers
- CContinuous Access Evaluation for Microsoft Exchange Online
- Dconnections to the on-premises apps
How the community answered
(42 responses)- A50% (21)
- B19% (8)
- D31% (13)
Explanation
Global Secure Access compliant network check integrates with Conditional Access to verify traffic routes through the Global Secure Access service. A is correct because third-party SaaS apps registered in the Microsoft Entra tenant can be protected with Conditional Access policies that enforce compliant network checks - the traffic is tunneled through Global Secure Access and verified. C is correct because Global Secure Access explicitly supports Continuous Access Evaluation (CAE) for Microsoft 365 services like Exchange Online, enabling near-real-time enforcement of policy changes. B is incorrect because the branch office computers are NOT enrolled in Intune - compliant network check requires devices to be Intune-managed or Entra-joined with the Global Secure Access client installed, which branch computers cannot satisfy. D is incorrect because on-premises apps published via Microsoft Entra application proxy use a different traffic path (the application proxy connector), and the compliant network check does not apply to that connector-based model in the same way.
Topics
Community Discussion
No community discussion yet for this question.