SC-300 · Question #395
Hotspot Question You have a Microsoft 365 subscription. You configure a Global Secure Access security profile named SecurityProfile1. You need to create a Conditional Access policy named CAPolicy1…
The correct answer is Target resources: Select apps; Network NEW: Configure Global Secure Access forwarding profiles. This question tests knowledge of how to link a Global Secure Access security profile to a Conditional Access policy in Microsoft Entra ID (formerly Azure AD). Two specific settings within the Conditional Access policy must be configured correctly to associate SecurityProfile1.
Question
Hotspot Question You have a Microsoft 365 subscription. You configure a Global Secure Access security profile named SecurityProfile1. You need to create a Conditional Access policy named CAPolicy1 that will use SecurityProfile1. Which two settings should you configure to ensure that CAPolicy1 uses SecurityProfile1? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point. Answer:
Answer Area
- Target resourcesSelect appsNo target resources selectedAll cloud appsSelect apps
- Network NEWConfigure Global Secure Access forwarding profilesNot configuredAny locationAll trusted locationsSelected locationsConfigure Global Secure Access forwarding profiles
Explanation
This question tests knowledge of how to link a Global Secure Access security profile to a Conditional Access policy in Microsoft Entra ID (formerly Azure AD). Two specific settings within the Conditional Access policy must be configured correctly to associate SecurityProfile1.
Approach. To use a Global Secure Access security profile in a Conditional Access policy, you must configure two settings: (1) Under 'Session' controls, select 'Use Global Secure Access security profile' and choose SecurityProfile1 - this is where the actual profile binding occurs. (2) Under 'Target resources' (Cloud apps), select 'Global Secure Access (Preview)' or 'All internet resources with Global Secure Access' as the target - this ensures the policy applies to traffic flowing through the Global Secure Access service. Without targeting the correct resource type, the security profile cannot be enforced, and without the Session control referencing the profile, CAPolicy1 would not apply SecurityProfile1's specific configurations.
Concept tested. Configuring Conditional Access policies to enforce Global Secure Access (Microsoft Entra Internet Access / Private Access) security profiles, specifically understanding that both the 'Target resources' (set to Global Secure Access traffic) and the 'Session' control (set to use the named security profile) must be configured together.
Topics
Community Discussion
No community discussion yet for this question.