QuestionQ13

Network architecture design

A customer asks an MSP to recommend a ZTA design for its globally distributed remote workforce. The requirements are as follows:

  • Authentication must be provided through the customer’s SAML identity provider.
  • Access must be blocked from countries where the business does not operate.
  • Add secondary authentication to the workflow to support passkeys.
  • Changes to a user’s device posture and hygiene must require reauthentication to the network.
  • Network access must originate only from corporate-owned devices.

Which solution should the MSP recommend to satisfy these requirements?

Explanation

A Zero Trust access design needs federated SSO to use the existing SAML identity provider, MFA that supports passkeys, geolocation controls to deny access from prohibited countries, continuous access evaluation to reassess and require reauthentication when relevant security conditions change, and trusted-endpoint enforcement to limit access to corporate-managed devices. Microsoft Entra Conditional Access supports country or region location blocking and compliant-device requirements, while passkeys can serve as an MFA method.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!