Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDMedium
A global enterprise uses Microsoft Entra ID to manage identities. They have several highly sensitive applications that process confidential financial data. The security team requires that users accessing these applications re-authenticate every 30 minutes, regardless of their previous sign-in activity, even if they have an active session. All other applications can use the default session duration. Which Conditional Access control should be configured to meet this requirement?
- ARequire multifactor authentication
- BPersistent browser session
- CSign-in frequency
- DRequire device to be marked as compliant
Show answer & explanationAnswer & explanation
Correct answer: C. Sign-in frequency
To enforce re-authentication at a specific interval, the 'Sign-in frequency' control within a Conditional Access policy is the appropriate setting. This allows administrators to define how often users must re-authenticate for specific applications.
Why the other options are wrong
- A. This ensures an extra layer of security but doesn't control the re-authentication interval.
- B. This setting allows users to remain signed in after closing and reopening their browser, which is contrary to the re-authentication requirement.
- D. This ensures the device meets compliance standards but does not enforce a specific re-authentication frequency.
Conditional Access Sign-in Frequency
A Microsoft Entra Conditional Access control that defines how often users are required to re-authenticate, even if they have an active session.
- Configured per policy, targeting specific applications or users.
- Overrides default session durations for specified scope.
- Enhances security for sensitive resources by enforcing regular re-authentication.
Memory trick: Conditions Apply: Grant Access, but Check Frequency and Device!