Security wants sign-ins from the office network to proceed normally, sign-ins from anywhere else to require a second factor, and any sign-in to the finance application from an unmanaged device to be refused outright. Which capability expresses all three rules?

Microsoft Certified: Azure Fundamentals (AZ-900), objective architecture-and-services. Azure architecture and services medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

The options

Correct Conditional Access policies

Correct. Conditional Access evaluates signals at sign-in — the user, the location, the state of the device, the application being reached, the assessed risk — and applies a decision: allow, allow with extra requirements, or block.

Not correct Azure role-based access control assignments

Wrong. Role assignments decide what an already-authenticated principal may do to Azure resources. They have no visibility of where a sign-in came from or what device it used.

Not correct Turning on multifactor authentication for everybody, everywhere, always

Wrong. It satisfies one clause by ignoring the other two: office sign-ins get prompted anyway, and the finance application is still reachable from an unmanaged device. Blanket rules are what signal-based policies replace.

Not correct Resource locks on the finance application's resources

Wrong. A lock prevents a resource being deleted or modified by administrators. It cannot refuse a user's sign-in, which is what two of the three rules require.

Why

Conditional Access is the if-then layer of identity: if these signals hold, then require this or block. It is what makes multifactor authentication proportionate rather than constant, and it is where device state, location and risk enter the decision. Remember the division of labour — Conditional Access decides whether you get in and on what terms, role-based access control decides what you can touch once you are.

Where this comes from

Cited
Microsoft AZ-900 study guide skill area architecture-and-services.identity-access-security

Practise this

Reading one question is not practice. The trainer will draw a set from objective architecture-and-services and space the ones you get wrong.

Practise Microsoft Certified: Azure Fundamentals (AZ-900)

More questions on this objective

All questions on Azure architecture and services