Microsoft 365 FundamentalsDescribe core Microsoft 365 services and conceptsMedium

A Microsoft 365 administrator is configuring security settings for a new tenant. They want to ensure that all user identities are protected by requiring a second form of verification during sign-in, even if users are on a trusted network. Which Microsoft 365 security feature should the administrator implement?

  1. AMicrosoft Intune
  2. BConditional Access policies
  3. CMicrosoft Defender for Office 365
  4. DAzure Information Protection (AIP)
Show answer & explanation

Correct answer: B. Conditional Access policies

Conditional Access policies in Azure Active Directory (which underpins Microsoft 365) allow administrators to enforce specific requirements, such as multi-factor authentication (MFA), based on various conditions like user location, device, or application, even for trusted networks.

Why the other options are wrong

  • A. Microsoft Intune manages device and application policies but does not directly implement multi-factor authentication for user sign-ins across the tenant.
  • C. Microsoft Defender for Office 365 protects against threats in email and collaboration but does not directly control user sign-in authentication requirements.
  • D. Azure Information Protection focuses on classifying and protecting sensitive data, not on enforcing sign-in verification.

Conditional Access

A feature of Azure Active Directory that allows organizations to enforce policies for accessing resources based on conditions.

  • Enforces Multi-Factor Authentication (MFA)
  • Requires compliant devices or specific locations
  • Can block access or require password change
  • Part of Azure AD Premium P1/P2

Memory trick: Access is 'conditional' on fulfilling requirements like MFA, even on trusted networks.

More Describe core Microsoft 365 services and concepts questions