Microsoft 365 Administrator Expert MS-102 Practice Question
Your company has a Microsoft 365 E5 subscription. All corporate Windows 11 devices are onboarded to Microsoft Defender for Endpoint (MDE). After running Cloud Discovery in Microsoft Defender for Cloud Apps, you identify several high-risk services that must be blocked when accessed from managed devices, but employees must remain free to use the same services from personal or unmanaged devices. You need to implement the solution without deploying additional proxies, network appliances, or browser extensions. Which action should you take in Microsoft Defender for Cloud Apps?
Deploy the Defender for Cloud Apps log collector appliance to ingest firewall logs and configure an anomaly detection policy for the services.
Create a Defender for Cloud Apps session policy that blocks upload and download traffic for the services and set the apps to Monitored.
Create a Conditional Access policy that applies Conditional Access App Control in Block mode to the identified services.
Enable the Microsoft Defender for Endpoint integration, turn on automatic blocking of unsanctioned apps, and mark the identified services as Unsanctioned.
Integrating Microsoft Defender for Endpoint with Microsoft Defender for Cloud Apps creates a native, client-based enforcement channel. When the integration is enabled and the option to automatically block unsanctioned apps (also known as Enforce network restrictions) is turned on, any app that you tag as Unsanctioned in Defender for Cloud Apps is blocked directly on devices that are managed by Defender for Endpoint. The block relies on the MDE network protection capability and therefore requires no extra infrastructure or browser plug-ins. Conditional Access App Control or session policies can control sanctioned apps in real time but do not selectively block only managed devices without using reverse proxy redirection. Deploying a log collector only imports discovery data and does not provide enforcement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does enabling Microsoft Defender for Endpoint integration achieve?
Open an interactive chat with Bash
How does Microsoft Defender for Endpoint block unsanctioned apps?
Open an interactive chat with Bash
Why are Conditional Access App Control or session policies not suitable for this scenario?
Open an interactive chat with Bash
Microsoft 365 Administrator Expert MS-102
Manage security and threats by using Microsoft Defender XDR
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .