Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantHard
A Microsoft 365 administrator is required to implement a security policy that automatically blocks access to Microsoft 365 applications if a user's sign-in is detected as 'high risk' by Azure AD Identity Protection. Which type of policy in Azure AD should the administrator configure?
- AConditional Access policy
- BMicrosoft Defender for Cloud Apps policy
- CIdentity Protection user risk policy
- DAzure AD Privileged Identity Management (PIM) policy
Show answer & explanationAnswer & explanation
Correct answer: A. Conditional Access policy
While Azure AD Identity Protection detects the risk, Conditional Access policies are the enforcement engine. A Conditional Access policy can be configured to use Identity Protection's sign-in risk level as a condition to then block access.
Why the other options are wrong
- B. Defender for Cloud Apps policies focus on controlling app usage and data, not on initial access blocking based on sign-in risk detections from Azure AD.
- C. Identity Protection user risk policies trigger actions based on overall user risk, not specifically sign-in risk for blocking access to M365 apps. Conditional Access is the mechanism for enforcement.
- D. PIM policies manage just-in-time access for privileged roles and are not directly used for blocking access based on sign-in risk for general users.
Conditional Access with Identity Protection Risk
An Azure AD Conditional Access policy that uses sign-in risk levels (detected by Azure AD Identity Protection) as a condition to enforce access controls like blocking access or requiring MFA.
- Identity Protection detects the risk, Conditional Access enforces the action.
- Can be configured to block, require MFA, or require password change.
- Targets specific cloud apps, users, and risk levels.
Memory trick: Risk gets flagged, Conditional Access seals the deal.