Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantHard

A Microsoft 365 administrator is required to implement a security policy that automatically blocks access to Microsoft 365 applications if a user's sign-in is detected as 'high risk' by Azure AD Identity Protection. Which type of policy in Azure AD should the administrator configure?

  1. AConditional Access policy
  2. BMicrosoft Defender for Cloud Apps policy
  3. CIdentity Protection user risk policy
  4. DAzure AD Privileged Identity Management (PIM) policy
Show answer & explanation

Correct answer: A. Conditional Access policy

While Azure AD Identity Protection detects the risk, Conditional Access policies are the enforcement engine. A Conditional Access policy can be configured to use Identity Protection's sign-in risk level as a condition to then block access.

Why the other options are wrong

  • B. Defender for Cloud Apps policies focus on controlling app usage and data, not on initial access blocking based on sign-in risk detections from Azure AD.
  • C. Identity Protection user risk policies trigger actions based on overall user risk, not specifically sign-in risk for blocking access to M365 apps. Conditional Access is the mechanism for enforcement.
  • D. PIM policies manage just-in-time access for privileged roles and are not directly used for blocking access based on sign-in risk for general users.

Conditional Access with Identity Protection Risk

An Azure AD Conditional Access policy that uses sign-in risk levels (detected by Azure AD Identity Protection) as a condition to enforce access controls like blocking access or requiring MFA.

  • Identity Protection detects the risk, Conditional Access enforces the action.
  • Can be configured to block, require MFA, or require password change.
  • Targets specific cloud apps, users, and risk levels.

Memory trick: Risk gets flagged, Conditional Access seals the deal.

More Deploy and manage a Microsoft 365 tenant questions