-
Conditional access policy question
-
Your organization has an Azure AD subscription that is associated with the directory TD-Siargao.
You have been tasked to implement a conditional access policy.
The policy must require the DevOps group to use multi-factor authentication and a hybrid Azure AD joined device when connecting to Azure AD from untrusted locations.
Solution: Create a conditional access policy and enforce session control.
Does the solution meet the goal?
In the answer this explanation is given:
> There are two types of access controls in a conditional access policy:
- Grant – enforces grant or block access to resources.
- Session – enable limited experiences within specific cloud applications
I suppose this is correct… however I researched it and I think the following explanation provides a better reason why which answer is correct:
Session controls manage the user’s experience during the session AFTER access is granted.
-
Hello samabc,
Thanks for the feedback.
We’ll definitely take that clarification into account as we continue refining the content.
Regards,
JR @ Tutorials Dojo
Log in to reply.