Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantMedium
A Microsoft 365 administrator is implementing a new security policy that requires all users to authenticate using multi-factor authentication (MFA) when accessing SharePoint Online from outside the corporate network. Additionally, if the sign-in is detected as high risk by Azure AD Identity Protection, access should be blocked entirely. Which type of policy should the administrator configure?
- AMicrosoft Intune device compliance policy
- BMicrosoft 365 Defender attack surface reduction rule
- CAzure AD Conditional Access policy
- DAzure AD Identity Protection user risk policy
Show answer & explanationAnswer & explanation
Correct answer: C. Azure AD Conditional Access policy
Azure AD Conditional Access policies are used to enforce specific access requirements, such as requiring MFA based on network location and blocking access based on sign-in risk detected by Identity Protection.
Why the other options are wrong
- A. Intune device compliance policies ensure device health but don't directly enforce MFA or block access based on sign-in risk.
- B. Attack surface reduction rules are part of endpoint security and prevent malicious actions on devices, not access control to cloud apps.
- D. Identity Protection user risk policies act on user risk levels, but Conditional Access is the engine that applies specific actions like MFA or blocking based on these signals.
Azure AD Conditional Access
A feature of Azure Active Directory that enables organizations to enforce policies for accessing resources based on specific conditions, such as user, device, location, and real-time risk detections.
- Acts as a policy engine for access decisions.
- Combines 'If' (conditions) and 'Then' (controls).
- Can enforce MFA, device compliance, or block access.
Memory trick: Conditional Access: If this, then that for security.