Your Azure DevOps organization is accessible only to Azure Active Directory users. You must ensure access is allowed only from devices on the company’s on-premises network. Which action should you take?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure a conditional access policy in Azure Active Directory..
Why this is the answer
To restrict access to Azure DevOps to only devices on your company's on-premises network, you should configure a conditional access policy in Azure Active Directory (Azure AD). Conditional Access policies allow you to enforce specific conditions, such as requiring users to be on a trusted network or using a compliant device, before granting access to cloud apps like Azure DevOps. This directly addresses the requirement of limiting access based on network location. Assigning devices to a security group is useful for managing permissions but doesn't inherently restrict access based on network location. Creating a Group Policy Object (GPO) is for managing Windows client and server settings within an on-premises Active Directory domain, not for controlling access to cloud services like Azure DevOps based on network conditions. Configuring Security in Project Settings in Azure DevOps manages permissions within the DevOps organization itself (e.g., who can access a specific project or repository), but it doesn't enforce network-level access restrictions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed