Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDHard

A global enterprise uses Microsoft Entra ID to manage identities. They have several highly sensitive applications that require an additional layer of security. You need to implement a solution that ensures users accessing these applications are consistently prompted for a second verification factor, even if they have recently satisfied MFA for another application. Which Microsoft Entra Conditional Access session control should you configure?

  1. ACustom controls
  2. BPersistent browser session
  3. CSign-in frequency
  4. DUse app enforced restrictions
Show answer & explanation

Correct answer: C. Sign-in frequency

The 'Sign-in frequency' session control in Conditional Access allows you to specify how often users are required to re-authenticate, including re-performing MFA. Setting a low sign-in frequency (e.g., 'Every time') for sensitive applications ensures consistent MFA prompts.

Why the other options are wrong

  • A. Custom controls integrate with external systems and are not directly used to enforce sign-in frequency within Entra ID.
  • B. Persistent browser session keeps users signed in for longer, which is the opposite of the requirement.
  • D. 'Use app enforced restrictions' relies on the application's capabilities, which might not enforce MFA every time.

Conditional Access Sign-in Frequency

A session control in Microsoft Entra Conditional Access that defines how often users are required to re-authenticate.

  • Can be set for 'Every time', 'Periodically', or 'Once'.
  • Controls the re-prompting for all authentication factors, including MFA.
  • Useful for enforcing stricter authentication requirements for sensitive applications.

Memory trick: Control Sessions with Care and Consistency.

More Implement and manage Microsoft Entra ID questions