Valid AZ-304 Dumps shared by ExamDiscuss.com for Helping Passing AZ-304 Exam! ExamDiscuss.com now offer the newest AZ-304 exam dumps, the ExamDiscuss.com AZ-304 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com AZ-304 dumps with Test Engine here:
You are designing an Azure web app that will use Azure Active Directory (Azure AD) for authentication. You need to recommend a solution to provide users from multiple Azure AD tenants with access to App1. The solution must ensure that the users use Azure Multi-Factor Authentication (MFA) when they connect to App1. Which two types of objects should you include in the recommendation? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Correct Answer: A,B
A: The Conditional Access feature in Azure Active Directory (Azure AD) offers one of several ways that you can use to secure your app and protect a service. Conditional Access enables developers and enterprise customers to protect services in a multitude of ways including: * Multi-factor authentication * Allowing only Intune enrolled devices to access specific services * Restricting user locations and IP ranges B: Conditional Access policies are powerful tools, we recommend excluding the following accounts from your policy: * Service accounts and service principals. If your organization has these accounts in use in scripts or code, consider replacing them with managed identities. Incorrect Answers: E: Application security groups enable you to configure network security as a natural extension of an application's structure, allowing you to group virtual machines and define network security policies based on those groups Reference: https://docs.microsoft.com/en-us/azure/active-directory/develop/v2-conditional-access-dev-guide https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy- azure-management