Which Azure service can restrict resource access based on a user's department and role?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure AD Conditional Access.
Why this is the answer
Azure AD Conditional Access is the correct answer because it allows you to enforce policies that evaluate conditions like user group (department), role, location, device, and application to grant or block access to resources. This directly addresses the requirement of restricting access based on a user's department and role. Azure Tags are used for organizing and categorizing resources, not for enforcing access control. Azure App Gateway is a web traffic load balancer that enables you to manage traffic to your web applications, but it doesn't restrict access based on user attributes like department or role. Azure DNS provides domain name resolution and doesn't offer access control features for resources.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed