Microsoft Azure Security Technologies (AZ-500)

Disable ads (and more) with a membership for a one time $4.99 payment

Study for the Microsoft Azure Security Technologies (AZ-500) exam. Prepare with well-structured questions and detailed explanations. Enhance your understanding and improve your readiness for the certification exam!

Practice this question and more.


What should you set the Enable policy setting to when using the What if tool for a Conditional Access policy?

  1. Off

  2. On

  3. Report only

  4. Enabled

The correct answer is: Report only

When using the What If tool within the context of Conditional Access policies in Azure, setting the policy to "Report only" is appropriate. The What If tool is designed to simulate the impact of a Conditional Access policy without enforcing any changes. By selecting "Report only," you're able to preview how the policy will affect user access to resources without actually applying the policy in a way that could inadvertently block or change access for users. This mode allows administrators to see potential impacts and outcomes based on current user states and attributes, helping them to make informed decisions about the implementation of the policy. It presents a clear view of the users who would be affected if the policy were enforced, allowing for adjustments and refinements before moving to a more restrictive or applied state. Other settings like "Off" or "Enabled" would not provide the desired simulation capability since "Off" would mean the policy is not active, and "Enabled" activates the policy, which does not allow for pre-emptive impact assessment. "On," in this context, is less specific than "Report only" because it may imply enforcement of access controls rather than just assessment. Thus, "Report only" facilitates a risk-free review process.