
Ultimate access to all questions.
In the context of securing high-risk applications, such as those handling financial transactions, Microsoft Entra Conditional Access policies offer a robust framework for enforcing strict security measures. Considering the need for both security and usability, which of the following statements accurately describe how these policies can be tailored to mitigate risks? (Choose two options from A, B, C, D)
A
Conditional Access policies only support basic access controls and cannot be tailored for high-risk applications.
B
Conditional Access policies allow for the creation of custom rules based on user, device, and application risk levels to enforce strict access controls.
C
Conditional Access policies are only applicable to cloud applications and do not support on-premises high-risk applications.
D
Conditional Access policies can enforce additional controls such as requiring Multi-Factor Authentication (MFA), restricting access to trusted devices, or limiting access based on user location.