Azure Active Directory Terms of Use Configuration for Access Control

Ensure Only Users Who Accept Terms of Use Can Access Resources in Your Microsoft 365 Tenant

Question

You have a Microsoft 365 tenant.

In Azure Active Directory (Azure AD), you configure the terms of use.

You need to ensure that only users who accept the terms of use can access the resources in the tenant.

Other users must be denied access.

What should you configure?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

C.

https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/terms-of-use

The correct answer to this question is C. a conditional access policy in Azure AD.

Explanation: Conditional Access is a feature in Azure Active Directory that allows you to set policies that determine the conditions under which users can access organizational resources. By configuring a conditional access policy, you can enforce the terms of use and require users to accept them before they can access the resources in your Microsoft 365 tenant.

To configure the policy, you need to define the following:

  1. Assignments: The users or groups to whom the policy applies.

  2. Cloud apps: The cloud apps that the policy applies to.

  3. Conditions: The conditions under which the policy applies, such as device state, location, and client application.

  4. Access controls: The access controls that the policy enforces, such as requiring multi-factor authentication or blocking access entirely.

To enforce the terms of use, you can configure a conditional access policy that requires users to accept the terms of use before they can access the resources in the tenant. You can configure the policy to deny access to users who have not accepted the terms of use.

Therefore, the correct answer to this question is C. a conditional access policy in Azure AD. The other options, such as an access policy in Microsoft Cloud App Security, Terms and conditions in Microsoft Endpoint Manager, and a compliance policy in Microsoft Endpoint Manager, are not relevant to this scenario.