Worth 22% of the Microsoft Cloud and AI Security Engineer (SC-500) exam. CertClue has 46 questions on this objective.
What this objective covers
Conditional Access Signals, Decisions and Session Controls
Conditional Access is Microsoft Entra ID's if-then policy engine. It evaluates a set of signals about a sign-in attempt, applies a decision that either blocks or grants access, and can then constrain the resulting session. Knowing which piece belongs where is the fastest way to eliminate wrong answers on scenario questions.
Exam tip. If a scenario describes something happening only after sign-in succeeds, such as limiting downloads or forcing frequent re-authentication, that is a session control, not a grant control. Read the verb carefully; 'require' usually signals a grant control, 'restrict' or 'limit during the session' usually signals a session control.
Privileged Identity Management: Eligible vs Active Assignments
Microsoft Entra Privileged Identity Management (PIM) exists to remove standing privileged access. Instead of a user holding an administrator role permanently, PIM makes the role eligible, and the user activates it only when needed, for a limited time.
Exam tip. A question describing standing, always-on administrator access as a finding to fix is almost always solved by converting that assignment from active to eligible in PIM, not by removing the role entirely.
Practice questions
Free, with the answer and the reasoning. No account needed.
1. Hollowmere Underwriters wants employees to satisfy multi-factor authentication whenever they sign in to the Azure portal from outside the corporate office IP range, while allowing seamless sign-in from trusted office locations. Which approach should the security team configure?
A. Enable Microsoft Entra security defaults for the entire tenant
B. Create a Conditional Access policy that targets all locations except a named trusted location and requires multi-factor authenticationcorrect
C. Configure Privileged Identity Management for the affected users
D. Enable Microsoft Entra Password Protection with a custom banned password list
Conditional Access lets you scope a policy by named location, excluding trusted office IP ranges, and require MFA only for sign ins outside that boundary. Security defaults apply MFA uniformly to all users everywhere and cannot exclude trusted locations. PIM manages privileged role activation, not general sign in conditions. Password Protection blocks weak passwords, it does not enforce MFA.
2. An administrator at Everdale Distribution disables a compromised user's account, but the user's existing access token remains valid for up to an hour, allowing continued access to resources until the token expires. Which feature should be enabled so that critical events like account disablement revoke access in near real time instead of waiting for token expiration?
A. A stricter Conditional Access sign-in frequency setting
B. Continuous Access Evaluationcorrect
C. A recurring access review for the affected resource
D. Identity Protection user risk policy
Continuous Access Evaluation subscribes to critical events such as account disablement, password reset, and location change, revoking tokens near real time instead of waiting for expiration. Sign-in frequency only affects how often reauthentication is required going forward, and risk policies act at sign-in time, not against a live session.
Work the whole objective
The full Microsoft Cloud and AI Security Engineer bank, the study notes behind these summaries, and a readiness score that tells you which objective to revise next. Free, no paid tier.