Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDMedium
A large enterprise uses Microsoft Entra ID and has implemented Microsoft Entra Connect for hybrid identity. They have a strict security policy that requires all Global Administrators to re-authenticate every hour when accessing sensitive resources, regardless of other Conditional Access policies. Other users should have a normal sign-in frequency. You need to configure this requirement. Which Conditional Access control should you use?
- AGrant control: Require multi-factor authentication
- BSession control: Sign-in frequency
- CGrant control: Require device to be marked as compliant
- DSession control: Use app enforced restrictions
Show answer & explanationAnswer & explanation
Correct answer: B. Session control: Sign-in frequency
The 'Sign-in frequency' session control within Conditional Access policies directly addresses the requirement to force re-authentication after a specified time period (e.g., 1 hour) for specific user groups like Global Administrators.
Why the other options are wrong
- A. Requiring MFA enforces multi-factor authentication but doesn't control the frequency of re-authentication.
- C. Requiring a compliant device checks device health but doesn't control sign-in frequency.
- D. App enforced restrictions are for controlling access within specific applications, not for global re-authentication frequency.
Conditional Access Sign-in Frequency
A session control in Microsoft Entra Conditional Access that defines how often users are required to re-authenticate when accessing resources protected by the policy.
- Can be configured to enforce re-authentication after a specific duration (e.g., 1 hour, 1 day).
- Helps enforce stricter security for privileged accounts or sensitive applications.
- Applied as a session control within a Conditional Access policy.
- Can override default token lifetimes for enhanced security.
Memory trick: Conditional Access: Control How Often Users Sign-In.