Microsoft365テナントがあります。 すべてのユーザーは、Windows 10を実行するコンピューターを持っています。ほとんどのコンピューターは会社所有であり、Azure Active Directory(Azure AD)に参加しています。一部のコンピューターはユーザー所有であり、AzureADにのみ登録されます。 ユーザーが所有するコンピューターでMicrosoftSharePoint Onlineに接続するユーザーが、ファイルをダウンロードまたは同期できないようにする必要があります。他のユーザーを制限してはなりません。 どのポリシータイプを作成する必要がありますか?
正解:B
SC-300 teaches using Conditional Access session controls with SharePoint and OneDrive to protect data on unmanaged devices. The documentation states: "Session controls allow limiting the experience within cloud apps, including Use app enforced restrictions to apply SharePoint Online policies like block download on unmanaged devices." It defines unmanaged as devices that are "not compliant or not hybrid Azure AD joined." The scenario requires blocking download/sync only for user-owned (registered) devices, while allowing access for company-owned (joined/compliant) devices-precisely what session controls achieve. Activity or app-discovery policies in Microsoft Defender for Cloud Apps (MCAS) are not required here, and client apps conditions target protocol types rather than shaping in-app actions. Therefore, create a Conditional Access policy targeting SharePoint Online, scope to devices that are not compliant or not hybrid joined, and set Session # Use app enforced restrictions (or Sign-in frequency + Conditional Access App Control) to block download, satisfying the SC-300 guidance for selective data exfiltration protection.