SC-100 · Question #296
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets…
The correct answer is A. Yes. To allow access to only low-risk external SaaS apps in a Microsoft 365 environment with Defender XDR and Intune, you can use Microsoft Entra Conditional Access policies. These policies can leverage Learn Microsoft's Defender for Endpoint data to restrict access based on device…
Question
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen. You have a Microsoft 365 subscription that uses Microsoft Defender XDR. The subscription contains 500 devices that are enrolled in Microsoft Intune. The subscription contains 500 users that connect to external software as a service (SaaS) apps by using the devices. You need to implement a solution that meets the following requirements:
- Allows user access to SaaS apps that Microsoft has identified as low
risk
- Blocks user access to Saas apps that Microsoft has identified as high
risk Solution: From Microsoft Defender for Cloud Apps, you configure SaaS security posture management (SSPM) and create an access policy. Does this meet the goal?
Options
- AYes
- BNo
How the community answered
(51 responses)- A84% (43)
- B16% (8)
Explanation
To allow access to only low-risk external SaaS apps in a Microsoft 365 environment with Defender XDR and Intune, you can use Microsoft Entra Conditional Access policies. These policies can leverage Learn Microsoft's Defender for Endpoint data to restrict access based on device compliance and threat level. Specifically, you can create policies that require a device to be compliant or have an app protection policy applied before allowing access to specific SaaS https://learn.microsoft.com/en-us/defender-cloud-apps/posture-overview https://learn.microsoft.com/en-us/defender-cloud-apps/proxy-intro-aad
Topics
Community Discussion
No community discussion yet for this question.