During an AZ-900 study session, a municipal IT trainee asks what Conditional Access is for—without needing full policy JSON. Which statement best describes its purpose?
Select an answer to reveal the explanation.
Short Explanation
Keep Conditional Access at the "purpose" level for Fundamentals: look at signals, then allow, block, or demand MFA. Nobody needs to hand-write policy JSON for AZ-900. That deeper authoring belongs elsewhere.
Full Explanation
At Azure Fundamentals depth, Conditional Access is described as policy-based access control driven by identity signals. Candidates should know the purpose—evaluate conditions and enforce controls—not author full Conditional Access policy documents or Sentinel automation. Distractors that turn it into ARM, billing freezes, or AZ-500 SOAR tooling miss the mark.