Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard

A company uses Azure Active Directory (Azure AD) with several applications registered. They want to ensure that users accessing a specific sensitive application from an untrusted network location are prompted for multi-factor authentication (MFA), even if they have previously satisfied MFA for other applications in the same session. What should you configure?

  1. AAn Azure AD Identity Protection policy
  2. BAn Azure AD Multi-Factor Authentication setting for per-user enforcement
  3. CA Conditional Access policy with a session control
  4. DAn Azure AD PIM (Privileged Identity Management) role activation
Show answer & explanation

Correct answer: C. A Conditional Access policy with a session control

A Conditional Access policy can be configured to target specific applications and user conditions (like network location). The 'Require reauthentication' session control within Conditional Access forces users to re-satisfy MFA, even if they have a valid MFA token from a previous authentication, ensuring MFA is performed again for the sensitive application under the specified conditions.

Why the other options are wrong

  • A. Identity Protection policies primarily deal with risk detection and automated responses, not forcing reauthentication for specific apps/conditions.
  • B. Per-user MFA enforcement is a legacy method and does not allow granular control based on application or network location within a session.
  • D. PIM is for managing and elevating access to privileged roles, not for enforcing MFA based on application or network conditions.

Conditional Access Session Controls

Conditional Access session controls in Azure AD allow organizations to enforce specific requirements during a user's session, such as requiring reauthentication or controlling access to cloud apps.

  • Applies to cloud apps access.
  • Can enforce reauthentication during a session.
  • Integrates with other Conditional Access conditions like location and device state.

Memory trick: Conditional Access is like a 'Security Gatekeeper' that checks conditions and applies session rules.

More Manage Azure identities and governance questions