Microsoft 365 FundamentalsDescribe core Microsoft 365 services and conceptsMedium
A Microsoft 365 administrator is configuring security settings for a new tenant. They want to ensure that all user identities are protected by requiring a second form of verification during sign-in, even if users are on a trusted network. Which Microsoft 365 security feature should the administrator implement?
- AMicrosoft Intune
- BConditional Access policies
- CMicrosoft Defender for Office 365
- DAzure Information Protection (AIP)
Show answer & explanationAnswer & explanation
Correct answer: B. Conditional Access policies
Conditional Access policies in Azure Active Directory (which underpins Microsoft 365) allow administrators to enforce specific requirements, such as multi-factor authentication (MFA), based on various conditions like user location, device, or application, even for trusted networks.
Why the other options are wrong
- A. Microsoft Intune manages device and application policies but does not directly implement multi-factor authentication for user sign-ins across the tenant.
- C. Microsoft Defender for Office 365 protects against threats in email and collaboration but does not directly control user sign-in authentication requirements.
- D. Azure Information Protection focuses on classifying and protecting sensitive data, not on enforcing sign-in verification.
Conditional Access
A feature of Azure Active Directory that allows organizations to enforce policies for accessing resources based on conditions.
- Enforces Multi-Factor Authentication (MFA)
- Requires compliant devices or specific locations
- Can block access or require password change
- Part of Azure AD Premium P1/P2
Memory trick: Access is 'conditional' on fulfilling requirements like MFA, even on trusted networks.