You have an Azure subscription and 100 Windows 10 devices. Ensure only users on devices with the latest security patches can access Azure Active Directory (Azure AD)-integrated applications. What should you implement?
Choose an answer
Tap an option to check your answer.
Correct answer: a conditional access policy.
Why this is the answer
A conditional access policy is the correct choice because it allows you to enforce conditions, such as requiring compliant devices (devices with the latest security patches), before granting access to Azure AD-integrated applications. This directly addresses the requirement to ensure only users on secure devices can access applications. Azure Bastion provides secure RDP/SSH access to virtual machines, not conditional access for applications. Azure Firewall filters network traffic to and from Azure resources, but doesn't enforce device compliance for application access. Azure Policy helps enforce organizational standards and assess compliance for Azure resources, but it doesn't directly control application access based on device patch status in the same way Conditional Access does.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed