Microsoft Entra ID Conditional Access as the Core of Zero Trust
Your organization is implementing a zero-trust security model. You need to design a solution that continuously verifies user identity, device compliance, and access context before granting access to corporate resources. The solution should also support risk-based policies. Which Microsoft security capability should be at the core of this design?
Quick Answer
The answer is Microsoft Entra ID Conditional Access, as it serves as the core policy engine in a zero-trust security model by continuously evaluating signals like user identity, device compliance, location, and real-time risk before granting access to corporate resources. This capability directly supports the zero-trust principle of "never trust, always verify" by enforcing granular, context-aware access decisions based on the conditions present at each authentication request. On the Microsoft Cybersecurity Architect exam, this question tests your understanding of how Conditional Access acts as the central decision point that integrates with other services like Intune for device compliance and Microsoft Defender for Identity for risk signals, rather than being a standalone tool. A common trap is confusing Conditional Access with Microsoft Intune, which manages device policies but does not enforce access control, or with Microsoft Sentinel, which is a SIEM for monitoring, not a policy engine. Memory tip: think of Conditional Access as the "bouncer" that checks your ID, device, and risk score at the door, while other tools just provide the guest list or security cameras.
⚠ Common exam trap
Candidates often confuse Microsoft Intune's device compliance enforcement with the actual policy decision engine, not realizing that Intune provides the device compliance state but Conditional Access is the component that evaluates that state along with identity and risk to make the access decision.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Conditional Access
Microsoft Entra ID Conditional Access is the core policy engine for zero-trust, enabling continuous verification of user identity, device compliance, and access context before granting resource access. It integrates with risk signals from Microsoft Entra ID Protection to enforce risk-based policies, such as requiring multi-factor authentication when sign-in risk is high. This aligns directly with the zero-trust principle of 'never trust, always verify' by evaluating conditions in real time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Identity
Why it's wrong here
Defender for Identity monitors on-premises Active Directory signals to detect compromised identities and lateral movement; it does not evaluate device compliance or apply conditional access at resource sign-in. It fits hybrid threat detection, whereas Microsoft Entra ID Conditional Access with risk policies enforces zero-trust verification.
- ✓
Microsoft Entra ID Conditional Access
Why this is correct
Microsoft Entra ID Conditional Access evaluates user identity, device compliance and sign-in context at every access request, and applies risk-based policies through signals such as user risk and sign-in risk. This continuous, context-aware evaluation is the core enforcement point of a zero-trust design.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a SIEM/SOAR platform that ingests logs, correlates detections and automates response; it observes and investigates events rather than gating access to resources. It suits security operations monitoring, while Microsoft Entra ID Conditional Access evaluates identity, device and risk signals before granting access.
- ✗
Microsoft Intune
Why it's wrong here
Intune enforces device compliance and configuration, but it cannot evaluate user risk or sign-in context, so it cannot serve as the policy engine. It is tempting because device compliance is one zero-trust signal; Intune would be correct for managing device enrolment and configuration baselines, not for continuous, risk-based access decisions.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization is implementing a zero-trust security model and needs to ensure that all access to cloud resources is verified in real-time. You plan to use Microsoft Entra ID Conditional Access. Which policy component enforces real-time verification of user identity and device compliance before granting access?
easy- A.Enable Microsoft Secure Score
- B.Use Azure AD Application Proxy
- ✓ C.Conditional Access policy with conditions and grant controls
- D.Assign users and groups to the policy
Why C: Conditional Access policies with conditions and grant controls enforce real-time verification by evaluating signals such as user identity, device compliance (via Microsoft Intune), and location before allowing access to cloud resources. The grant controls block or require multi-factor authentication (MFA) or device compliance, ensuring zero-trust principles of explicit verification and least privilege.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.