SC-200 Manage a security operations environment Practice Question
You are a security analyst at a company that uses Microsoft Sentinel. You need to ensure that only users with a specific tag in Microsoft Entra ID can access the Sentinel workspace. Which Azure feature should you use?
⚠ Common exam trap
A common mix-up: candidates confuse Azure RBAC with Conditional Access, assuming that RBAC conditions on tags can control initial access, when in fact RBAC only controls authorization after authentication, whereas Conditional Access controls authentication itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a Conditional Access policy in Microsoft Entra ID.
Conditional Access policies in Microsoft Entra ID can enforce access controls based on user attributes, including tags. By configuring a Conditional Access policy that grants access to Microsoft Sentinel only if the user has a specific tag, you can restrict workspace access at the authentication layer before any Azure RBAC evaluation occurs. This is the correct approach because Conditional Access operates at the identity level, directly controlling which users can authenticate to the Sentinel workspace.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign Azure RBAC roles with a condition on the tag.
Why it's wrong here
Azure RBAC with tag conditions implements attribute-based access control (ABAC), which can constrain the actions a user is permitted to perform on Azure resources—for example, allowing a user to only manage VMs whose environment tag matches a value. However, RBAC is an authorization engine that operates after authentication; it has no ability to prevent a user from signing in to the Azure portal or to filter the portal session based on a tag belonging to the user. Therefore, Azure RBAC with a tag condition can limit resource operations but cannot gate portal access itself.
- ✗
Use Microsoft Entra Privileged Identity Management (PIM) to require approval for access.
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) is designed to govern just-in-time activation and approval of privileged Microsoft Entra ID roles and Azure RBAC roles. A PIM approval flow can require a user to request elevation, provide justification, or satisfy multi-factor authentication, but it has no concept of a user or resource tag and cannot be used to independently deny or allow Azure portal sign-in. Even when PIM is enabled, a user with an ordinary account can still access the portal unless another identity policy explicitly blocks that session based on an attribute such as a tag.
- ✗
Apply an Azure Policy to deny access if the user does not have the tag.
Why it's wrong here
Azure Policy is a resource governance service that evaluates whether Azure resources comply with rules—such as requiring a certain tag on resource groups or VMs—and can deny or audit deployments that violate those rules. Its deny effect is applied during Azure Resource Manager operations and is based on resource properties, not on the identity or sign-in context of the user. Because Azure Policy cannot inspect a user's account attributes or their authentication session, it cannot stop a user from accessing the Azure portal; it can only enforce that the resources created by that user carry the required tags.
- ✓
Configure a Conditional Access policy in Microsoft Entra ID.
Why this is correct
A Conditional Access policy in Microsoft Entra ID acts as a gatekeeper during the authentication process, evaluating signals before a sign-in token is issued. If the policy targets the Microsoft Azure Management application, it can require a user to have a specific tag or identity attribute—often represented as a group membership or custom security attribute—before allowing access to the Azure portal. This makes Conditional Access the correct identity-driven control for blocking portal access, because it evaluates the user's identity and session rather than relying on resource-level RBAC, PIM, or Azure Policy.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.