Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDHard
A global enterprise uses Microsoft Entra ID to manage identities. They have several highly sensitive applications that require an additional layer of security. You need to implement a solution that ensures users accessing these applications are consistently prompted for a second verification factor, even if they have recently satisfied MFA for another application. Which Microsoft Entra Conditional Access session control should you configure?
- ACustom controls
- BPersistent browser session
- CSign-in frequency
- DUse app enforced restrictions
Show answer & explanationAnswer & explanation
Correct answer: C. Sign-in frequency
The 'Sign-in frequency' session control in Conditional Access allows you to specify how often users are required to re-authenticate, including re-performing MFA. Setting a low sign-in frequency (e.g., 'Every time') for sensitive applications ensures consistent MFA prompts.
Why the other options are wrong
- A. Custom controls integrate with external systems and are not directly used to enforce sign-in frequency within Entra ID.
- B. Persistent browser session keeps users signed in for longer, which is the opposite of the requirement.
- D. 'Use app enforced restrictions' relies on the application's capabilities, which might not enforce MFA every time.
Conditional Access Sign-in Frequency
A session control in Microsoft Entra Conditional Access that defines how often users are required to re-authenticate.
- Can be set for 'Every time', 'Periodically', or 'Once'.
- Controls the re-prompting for all authentication factors, including MFA.
- Useful for enforcing stricter authentication requirements for sensitive applications.
Memory trick: Control Sessions with Care and Consistency.