Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceEasy

A global organization uses Azure Active Directory (Azure AD) with multiple custom applications registered. They need to ensure that users are prompted for multi-factor authentication (MFA) only when they access these custom applications from outside the corporate network, but not when accessing from within the corporate network. Which Azure AD feature should be configured?

  1. AAzure AD Conditional Access policies
  2. BAzure AD Privileged Identity Management (PIM)
  3. CAzure AD Identity Protection risk policies
  4. DPer-user MFA enforcement in Azure AD
Show answer & explanation

Correct answer: A. Azure AD Conditional Access policies

Azure AD Conditional Access policies allow fine-grained control over access based on conditions like network location (corporate vs. untrusted). You can define a policy that requires MFA for specific applications when the access location is outside the corporate network.

Why the other options are wrong

  • B. PIM manages just-in-time access for privileged roles and is unrelated to network-based MFA for general users.
  • C. Identity Protection focuses on detecting and remediating identity-based risks, not on enforcing network-based MFA requirements for specific applications.
  • D. Per-user MFA enforcement applies MFA to a user regardless of their location or the application they are accessing, which does not meet the conditional requirement.

Azure AD Conditional Access

A feature of Azure Active Directory that allows organizations to enforce policies for accessing resources based on conditions such as user, device, location, and application.

  • Enables fine-grained access control.
  • Supports conditions like trusted IP ranges.
  • Can enforce MFA conditionally.

Memory trick: MFA is like a bouncer: sometimes needed, sometimes not, depending on where you enter.

More Manage Azure identities and governance questions