Your company has an Azure DevOps environment that can only be accessed by Azure Active Directory users.
You are instructed to make sure that the Azure DevOps environment can only be accessed from devices connected to the company's on-premises network.
Which of the following actions should you take?
Click on the arrows to vote for the correct answer
A. B. C. D.D
Conditional Access is a capability of Azure Active Directory. With Conditional Access, you can implement automated access control decisions for accessing your cloud apps that are based on conditions.
Conditional Access policies are enforced after the first-factor authentication has been completed.
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/overviewTo ensure that the Azure DevOps environment can only be accessed from devices connected to the company's on-premises network, you need to implement network-level security controls. One way to do this is by configuring conditional access in Azure Active Directory. Therefore, the correct answer is D.
Conditional access allows you to control access to your cloud apps based on specific conditions, such as the location of the user or device. You can create a policy that requires users to be on a company's on-premises network before they can access Azure DevOps. To configure conditional access in Azure Active Directory, you can follow these steps:
After you configure the conditional access policy, users will need to be on the company's on-premises network to access Azure DevOps. If a user attempts to access Azure DevOps from outside the network, they will be denied access.
Assigning devices to a security group (answer A) or creating a GPO (answer B) are not sufficient solutions to restrict access to Azure DevOps from devices on the company's on-premises network. These solutions can only control access at the device level and do not provide network-level security controls. Configuring Security in Project Settings from Azure DevOps (answer C) is also not a solution as it only deals with permissions and access to the projects within Azure DevOps and not with network-level security.