ホットスポットに関する質問
Microsoft Entraテナントがあります。このテナントには、Group1というセキュリティグループが含まれています。Group1には、会社のITサポートチームのメンバーが含まれています。
Azureサブスクリプションをお持ちです。このサブスクリプションには、Microsoft Entraに参加しているWindowsデバイスが800台、Microsoft Entraに登録されているWindowsデバイスが200台含まれています。
スタンドアロン macOS デバイスが 200 台あります。
Microsoft Entra に参加しており、Microsoft Entra ExtensionAttribute1 値が SecureWorkstation に設定されている 10 台の Windows デバイスを展開します。
次の要件を満たす条件付きアクセス ソリューションを推奨する必要があります。
- Windows 10 または Windows 11 を実行するデバイスからのみ Microsoft Entra リソースへのアクセスを許可します
- Windows Azureサービス管理APIのアクセスを制限します
次のユーザー:
- グループ1のメンバー
- 多要素認証 (MFA) を使用して認証するユーザー
- SecureWorkstationを搭載したデバイスから接続するユーザー
拡張属性1
ソリューションでは、必要なポリシーの数を最小限に抑え、セキュリティを最大限に高める必要があります。
推奨事項には何を含めるべきですか? 回答するには、回答領域で適切なオプションを選択してください。
注意: 正しい選択ごとに 1 ポイントが付与されます。

正解:

Explanation:
Box 1: 2
* Only allows access to Microsoft Entra resources from devices that run Windows 10 or Windows
11
Create one Conditional Access policy that uses one include device filter which includes only Windows 10 and Windows 11.
* Restricts Windows Azure Service Management API access to the following users:
The members of Group1
Users that authenticate by using multifactor authentication (MFA)
Users that connect from a device that has the SecureWorkstation ExtensionAttribute1 Create a second Conditional Access policy that includes Group1, requires MFA, and one include device for devices that has the SecureWorkstation ExtensionAttribute1. Grant access to Windows Azure Service Management API.
Box 2: Two include device filters
Reference:
https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-condition-filters-for- devices