SC-300 · Question #413
Hotspot Question You have a Microsoft 365 E5 subscription that has a Conditional Access policy named Policy1. You need to perform the following actions: - Create a Conditional Access App Control…
The correct answer is Use: Microsoft Entra admin center; Settings: Session. This question tests knowledge of Microsoft Defender for Cloud Apps (MCAS) integration with Azure AD Conditional Access to create and configure Conditional Access App Control policies.
Question
Answer Area
- UseMicrosoft Entra admin centerMicrosoft 365 admin centerMicrosoft Defender portalMicrosoft Entra admin centerMicrosoft Intune admin centerMicrosoft Purview compliance portal
- SettingsSessionSessionClient apps under ConditionsFilter for devices under ConditGrantTarget resources
Explanation
This question tests knowledge of Microsoft Defender for Cloud Apps (MCAS) integration with Azure AD Conditional Access to create and configure Conditional Access App Control policies.
Approach. Custom1 (a Conditional Access App Control custom policy) must be created in Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security), specifically under the 'Connected apps > Conditional Access App Control apps' section where you define custom session or access policies. In Policy1 (the Azure AD Conditional Access policy), you enable Conditional Access App Control under the 'Session' settings/controls - you select 'Use Conditional Access App Control' and choose 'Use custom policy' to link it to the policy defined in Defender for Cloud Apps. The 'Session' control in Conditional Access is the correct location because it governs real-time session monitoring and control, which is what Conditional Access App Control provides.
Concept tested. The concept tested is the integration between Azure AD Conditional Access and Microsoft Defender for Cloud Apps (MCAS) to implement Conditional Access App Control. Specifically, it tests: (1) that custom Conditional Access App Control policies are authored in Microsoft Defender for Cloud Apps, not in Azure AD, and (2) that these policies are invoked from the 'Session' controls (not Grant or other controls) within a Conditional Access policy in Azure AD.
Reference. Microsoft Docs: 'Protect apps with Microsoft Defender for Cloud Apps Conditional Access App Control' - https://learn.microsoft.com/en-us/defender-cloud-apps/proxy-intro-aad
Topics
Community Discussion
No community discussion yet for this question.