certslothcertsloth
SC-300/Topic 04

Microsoft / Associate

Conditional Access, Risk and Global Secure Access

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Evaluate signals, enforce controls, test before broad rollout.

Must remember

Conditional Access evaluates configured assignments/conditions and applies grant/session controls. Scope users, groups, workload identities where supported, target resources, locations, device state and risk carefully. Policies can combine; an applicable blocking policy can prevent access despite another allowing it. Report-only mode observes policy impact without enforcing its grant controls.

Use authentication strengths, compliant-device requirements and appropriate session controls to meet the actual requirement. Authentication context can request stronger checks for sensitive application actions; protected actions apply supported Conditional Access requirements to privileged operations. Test with sign-in logs and What If analysis, then a controlled user group, preserving monitored emergency access.

Identity Protection distinguishes user risk (likelihood an identity is compromised) from sign-in risk (risk in a particular authentication attempt). Investigate and remediate based on evidence; dismissing a detection is not the same as fixing a compromised account. Workload identity risk needs service-principal context and different remediation from a human password reset.

Continuous access evaluation enables supported resources to react to important changes more promptly, but it is not a universal instant revocation mechanism. Session lifetime, application-enforced restrictions and Defender for Cloud Apps session controls operate at different layers.

Global Secure Access includes Entra Internet Access and Private Access, with supported clients/connectors and traffic profiles. Private Access provides identity-aware access to private resources; Internet Access governs internet/SaaS traffic; the Microsoft traffic profile addresses supported Microsoft service traffic. Routing, enrollment and Conditional Access must align, or a policy may never see the intended traffic.

Choose under exam pressure

Requirement Choice and reason
Assess new policy impact safely Report-only, What If and controlled pilot evidence.
One suspicious login Investigate sign-in risk and associated user activity.
Identity-aware access to a private app Entra Private Access or appropriate Application Proxy scenario.

Traps

  • Report-only does not enforce the intended block.
  • A trusted named location alone is not a complete Zero Trust decision.

Active recall

1. User risk versus sign-in risk?

Compromised identity likelihood versus risk of a specific sign-in.

2. Why can two policies still block a user?

Applicable policies combine and a blocking result can prevail.

3. What does authentication context support?

Stronger conditional checks for a defined sensitive app action/context.

4. Why test emergency accounts separately?

They must remain usable during failures while being tightly monitored.

5. Why inspect traffic forwarding for Global Secure Access?

Unrouted or unsupported traffic may not pass through the intended control path.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.