Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDHard
A company is implementing Microsoft Entra Identity Protection to enhance security. They want to automatically block sign-ins from IP addresses that are detected as malicious. Additionally, for users signing in from 'risky' locations (e.g., unusual travel), they want to enforce multi-factor authentication (MFA). Which type of policy in Microsoft Entra Identity Protection should be configured to achieve these outcomes?
- ASign-in risk policy
- BMFA registration policy
- CUser risk policy
- DConditional Access policy
Show answer & explanationAnswer & explanation
Correct answer: A. Sign-in risk policy
A Microsoft Entra Identity Protection Sign-in risk policy evaluates the risk associated with a sign-in attempt in real-time. It can be configured to block access for high-risk sign-ins (e.g., from malicious IPs) and require MFA for medium-risk sign-ins (e.g., from unusual locations).
Why the other options are wrong
- B. MFA registration policy prompts users to register for MFA, not for enforcing it based on sign-in risk.
- C. User risk policy assesses the aggregate risk of a user account over time, not individual sign-in attempts.
- D. While Conditional Access policies can leverage Identity Protection risks, Identity Protection itself has dedicated sign-in risk policies for this specific purpose, providing the direct solution.
Microsoft Entra Identity Protection Sign-in Risk Policy
A Microsoft Entra Identity Protection Sign-in risk policy automatically detects and responds to real-time sign-in risks. It can enforce actions such as blocking access or requiring multi-factor authentication (MFA) based on the risk level associated with a user's sign-in attempt.
- Evaluates risk of individual sign-in attempts.
- Actions include block access or require MFA.
- Works with Microsoft Entra Conditional Access.
Memory trick: ID Protect: Risk-Based Reactions