nerdexam
Microsoft

SC-300 · Question #413

Hotspot Question You have a Microsoft 365 E5 subscription that has a Conditional Access policy named Policy1. You need to perform the following actions: - Create a Conditional Access App Control…

The correct answer is Use: Microsoft Entra admin center; Settings: Session. This question tests knowledge of Microsoft Defender for Cloud Apps (MCAS) integration with Azure AD Conditional Access to create and configure Conditional Access App Control policies.

Submitted by valeria.br· Mar 6, 2026Implement authentication and access management

Question

Hotspot Question You have a Microsoft 365 E5 subscription that has a Conditional Access policy named Policy1. You need to perform the following actions: - Create a Conditional Access App Control custom policy named Custom1. - Configure Policy1 to use Custom1. What should you use to create Custom1, and in which settings of Policy1 should you enable Conditional Access App Control? To answer, select the appropriate options in the answer area, NOTE: Each correct selection is worth one point. Answer:

Answer Area

  • UseMicrosoft Entra admin center
    Microsoft 365 admin centerMicrosoft Defender portalMicrosoft Entra admin centerMicrosoft Intune admin centerMicrosoft Purview compliance portal
  • SettingsSession
    SessionClient apps under ConditionsFilter for devices under ConditGrantTarget resources

Explanation

This question tests knowledge of Microsoft Defender for Cloud Apps (MCAS) integration with Azure AD Conditional Access to create and configure Conditional Access App Control policies.

Approach. Custom1 (a Conditional Access App Control custom policy) must be created in Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security), specifically under the 'Connected apps > Conditional Access App Control apps' section where you define custom session or access policies. In Policy1 (the Azure AD Conditional Access policy), you enable Conditional Access App Control under the 'Session' settings/controls - you select 'Use Conditional Access App Control' and choose 'Use custom policy' to link it to the policy defined in Defender for Cloud Apps. The 'Session' control in Conditional Access is the correct location because it governs real-time session monitoring and control, which is what Conditional Access App Control provides.

Concept tested. The concept tested is the integration between Azure AD Conditional Access and Microsoft Defender for Cloud Apps (MCAS) to implement Conditional Access App Control. Specifically, it tests: (1) that custom Conditional Access App Control policies are authored in Microsoft Defender for Cloud Apps, not in Azure AD, and (2) that these policies are invoked from the 'Session' controls (not Grant or other controls) within a Conditional Access policy in Azure AD.

Reference. Microsoft Docs: 'Protect apps with Microsoft Defender for Cloud Apps Conditional Access App Control' - https://learn.microsoft.com/en-us/defender-cloud-apps/proxy-intro-aad

Topics

#Conditional Access App Control#session policy#Defender for Cloud Apps#custom app control policy

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice