Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDMedium

A global enterprise uses Microsoft Entra ID to manage identities. They have several highly sensitive applications that process confidential financial data. The security team requires that users accessing these applications re-authenticate every 30 minutes, regardless of their previous sign-in activity, even if they have an active session. All other applications can use the default session duration. Which Conditional Access control should be configured to meet this requirement?

  1. ARequire multifactor authentication
  2. BPersistent browser session
  3. CSign-in frequency
  4. DRequire device to be marked as compliant
Show answer & explanation

Correct answer: C. Sign-in frequency

To enforce re-authentication at a specific interval, the 'Sign-in frequency' control within a Conditional Access policy is the appropriate setting. This allows administrators to define how often users must re-authenticate for specific applications.

Why the other options are wrong

  • A. This ensures an extra layer of security but doesn't control the re-authentication interval.
  • B. This setting allows users to remain signed in after closing and reopening their browser, which is contrary to the re-authentication requirement.
  • D. This ensures the device meets compliance standards but does not enforce a specific re-authentication frequency.

Conditional Access Sign-in Frequency

A Microsoft Entra Conditional Access control that defines how often users are required to re-authenticate, even if they have an active session.

  • Configured per policy, targeting specific applications or users.
  • Overrides default session durations for specified scope.
  • Enhances security for sensitive resources by enforcing regular re-authentication.

Memory trick: Conditions Apply: Grant Access, but Check Frequency and Device!

More Implement and manage Microsoft Entra ID questions