SC-100 · Question #53
Your company develops several applications that are accessed as custom enterprise applications in Azure Active Directory (Azure AD). You need to recommend a solution to prevent users on a specific…
The correct answer is D. Azure AD Conditional Access policies. Azure AD Conditional Access policies support Named Locations as a condition, allowing administrators to define specific countries or IP ranges. A policy can be configured to block access to the enterprise applications when the sign-in originates from any country on the…
Question
Your company develops several applications that are accessed as custom enterprise applications in Azure Active Directory (Azure AD). You need to recommend a solution to prevent users on a specific list of countries from connecting to the applications. What should you include in the recommendation?
Options
- Aactivity policies in Microsoft Defender for Cloud Apps
- Bsign-in risk policies in Azure AD Identity Protection
- Cdevice compliance policies in Microsoft Endpoint Manager
- DAzure AD Conditional Access policies
- Euser risk policies in Azure AD Identity Protection
How the community answered
(36 responses)- C3% (1)
- D94% (34)
- E3% (1)
Explanation
Azure AD Conditional Access policies support Named Locations as a condition, allowing administrators to define specific countries or IP ranges. A policy can be configured to block access to the enterprise applications when the sign-in originates from any country on the restricted list. This is a built-in, purpose-fit control for geography-based access restriction. Activity policies in Defender for Cloud Apps (A) are for session/activity monitoring, not blocking by country at sign-in. Sign-in risk policies (B) and user risk policies (E) in Identity Protection respond to anomaly-based risk scores, not explicit country lists. Device compliance policies in Endpoint Manager (C) control device health, not user location.
Topics
Community Discussion
No community discussion yet for this question.