Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantHard
A company has a Microsoft 365 E5 subscription. They want to ensure that all user accounts are protected with multi-factor authentication (MFA) and that access to Microsoft 365 services is blocked if a user signs in from an unfamiliar location or an infected device. Which Azure AD feature should be configured to achieve this comprehensive security posture?
- ASecurity Defaults
- BConditional Access
- CIdentity Protection
- DPrivileged Identity Management (PIM)
Show answer & explanationAnswer & explanation
Correct answer: B. Conditional Access
Conditional Access policies allow administrators to enforce MFA, block access, or require compliant devices based on various conditions like user location, device state (compliant/non-compliant), and sign-in risk (which can be informed by Identity Protection). This provides the granular control needed for the described scenario.
Why the other options are wrong
- A. Security Defaults provide a baseline MFA and block legacy authentication but lack the granularity for location-based or infected device blocking.
- C. Identity Protection detects risks (like unfamiliar location or infected device) but requires Conditional Access to *act* on those risks (e.g., block access or enforce MFA).
- D. PIM manages just-in-time access for privileged roles and is not directly used for enforcing MFA or blocking access based on location/device for all users.
Azure AD Conditional Access
An Azure AD feature that allows administrators to enforce specific access controls (e.g., MFA, device compliance) based on various conditions (user, location, device, application, sign-in risk).
- Requires Azure AD Premium P1 or P2 licenses.
- Works on an 'if-then' basis (If 'conditions' are met, then 'access controls' are applied).
- Can integrate with Azure AD Identity Protection for risk-based policies.
Memory trick: Think of Conditional Access as a smart traffic cop at your digital intersection, directing users based on their 'credentials' and 'vehicle' status.