Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A company wants to implement a multi-factor authentication (MFA) policy that applies to all users accessing financial applications, but only when they are outside the corporate network. Users accessing these applications from within the corporate network should not be prompted for MFA. Which Azure AD feature is best suited for this scenario?

  1. AAzure AD Privileged Identity Management (PIM)
  2. BAzure AD Conditional Access
  3. CAzure AD Multi-Factor Authentication (MFA) settings
  4. DAzure AD Identity Protection
Show answer & explanation

Correct answer: B. Azure AD Conditional Access

Azure AD Conditional Access allows you to define policies that enforce specific controls, like MFA, based on conditions such as user group, application, device state, and network location. This perfectly matches the requirement to apply MFA only when users are outside the corporate network.

Why the other options are wrong

  • A. PIM manages just-in-time access for privileged roles, not general user access policies.
  • C. Basic MFA settings enable MFA but lack the granularity to apply it conditionally based on network location for specific apps.
  • D. Identity Protection focuses on detecting and remediating identity risks, not configurable access policies based on location.

Azure AD Conditional Access

A powerful policy engine in Azure AD that allows organizations to enforce specific access controls (e.g., MFA, device compliance) based on various conditions such as user, application, location, device, and sign-in risk.

  • If-then statements for access control
  • Combines signals (user, location, device) to make decisions
  • Enforces controls like MFA, block access, or require compliant device

Memory trick: Conditional Access is like a smart bouncer: 'If this, then that!'

More Manage Azure identities and governance questions