Q: 19
DRAG DROP You have an Azure subscription that contains an Azure web app named Appl. You plan to configure a Conditional Access policy for Appl. The solution must meet the following requirements:
• Only allow access to App1 from Windows devices.
• Only allow devices that are marked as compliant to access Appl.
Which Conditional Access policy settings should you configure? To answer, drag the appropriate settings to the correct requirements. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
Drag & Drop
Discussion
Conditions to restrict to Windows devices, Grant for device compliance. Session is more about access duration and controls, not initial device state, so don't think it fits here. Seen Microsoft docs line up with this setup. Anyone see it done differently?
Conditions -> Only allow access to App1 from Windows devices, Grant -> Only allow devices that are marked as compliant.
Had something like this in a mock. You use Conditions for targeting OS (Windows), then under Grant, set compliance requirement. Pretty sure that's right, but open to corrections.
Had something like this in a mock. You use Conditions for targeting OS (Windows), then under Grant, set compliance requirement. Pretty sure that's right, but open to corrections.
Cloud apps or actions -> Only allow access to App1 from Windows devices
Grant -> Only allow devices that are marked as compliant
I picked Cloud apps for the Windows part since you can target specific apps directly, and Grant controls compliance settings. But now I'm thinking maybe Conditions is actually better for restricting OS type. Little unsure, open to feedback if someone has tried both options.
Grant -> Only allow devices that are marked as compliant
I picked Cloud apps for the Windows part since you can target specific apps directly, and Grant controls compliance settings. But now I'm thinking maybe Conditions is actually better for restricting OS type. Little unsure, open to feedback if someone has tried both options.
Be respectful. No spam.
