Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantHard

A Microsoft 365 administrator wants to implement a policy to automatically block access to Microsoft 365 services for any user account that exhibits a high sign-in risk. The company has a Microsoft 365 E5 subscription. Which Azure AD feature should the administrator configure to achieve this automated remediation?

  1. AAzure AD Conditional Access
  2. BMicrosoft Defender for Cloud Apps
  3. CAzure AD Privileged Identity Management (PIM)
  4. DAzure AD Identity Protection
Show answer & explanation

Correct answer: A. Azure AD Conditional Access

While Azure AD Identity Protection detects sign-in risks, it is Azure AD Conditional Access that provides the policy engine to enforce automated actions, such as blocking access, based on those detected risks. An administrator would create a Conditional Access policy that uses 'Sign-in risk (high)' as a condition and 'Block access' as the grant control.

Why the other options are wrong

  • B. Microsoft Defender for Cloud Apps (MDCA) provides advanced threat protection and app governance, but the direct automated blocking of Microsoft 365 access based on Azure AD sign-in risk is handled by Conditional Access.
  • C. PIM manages just-in-time access for privileged roles, not automated blocking based on sign-in risk for general users.
  • D. Identity Protection detects risks and can trigger actions, but the *enforcement mechanism* for blocking access based on risk is Conditional Access.

Conditional Access with Identity Protection Risk

Azure AD Conditional Access policies can leverage the risk detections from Azure AD Identity Protection to enforce automated security controls. This allows organizations to define policies that automatically block access, require MFA, or force password changes when a user's sign-in or user risk level is detected as high.

  • Requires Azure AD Premium P2 (included in M365 E5) for both Identity Protection and Conditional Access.
  • Identity Protection detects sign-in and user risks.
  • Conditional Access policies consume these risk signals as conditions.
  • Common actions include blocking access, requiring MFA, or requiring password change.

Memory trick: Risk detected, access denied: Conditional Access makes it unified.

More Deploy and manage a Microsoft 365 tenant questions