A financial services company uses Azure Active Directory (Azure AD) to manage access to its applications. Due to strict regulatory requirements, they must ensure that all users accessing highly sensitive applications are prompted for multi-factor authentication (MFA) every time, regardless of their location or device. Other, less sensitive applications should only require MFA if accessed from an unknown location or device. Which Azure AD Conditional Access policy configuration should be implemented to meet these requirements?
- AAssign a 'Require MFA' policy to the sensitive apps group, and a 'Block access' policy with 'MFA for unknown locations/devices' for other apps.
- BTwo separate Conditional Access policies: one 'Require MFA' for sensitive apps, and one 'MFA for unknown locations/devices' for less sensitive apps.
- CConfigure Azure AD Identity Protection to automatically enforce MFA for all sign-ins and then exclude sensitive applications.
- DA single Conditional Access policy targeting all applications, with a 'Require MFA' grant control and a condition for 'Risk level: High'.
Show answer & explanationAnswer & explanation
Correct answer: B. Two separate Conditional Access policies: one 'Require MFA' for sensitive apps, and one 'MFA for unknown locations/devices' for less sensitive apps.
To meet both requirements, two distinct Conditional Access policies are needed. One policy will target the highly sensitive applications and unconditionally require MFA. The second policy will target the less sensitive applications and require MFA only when specific conditions (like unknown location/device) are met. Conditional Access policies are evaluated independently.
Why the other options are wrong
- A. Using a 'Block access' policy for less sensitive apps with a condition for 'MFA for unknown locations/devices' is contradictory; it would block access, not prompt for MFA.
- C. Azure AD Identity Protection can enforce MFA based on risk, but it does not allow for 'always MFA' for specific apps while also having conditional MFA for others in the way described by the scenario without multiple policies.
- D. A single policy with 'Risk level: High' wouldn't differentiate between 'always MFA' for sensitive apps and 'conditional MFA' for less sensitive ones based purely on risk.
Azure AD Conditional Access Policy Application
Conditional Access policies are evaluated sequentially and independently. Each policy can target specific applications, users, locations, and device states to enforce granular access controls like MFA.
- Policies are 'if-then' statements.
- Multiple policies can apply to a single sign-in.
- Grant controls (like Require MFA) are enforced if all conditions are met.
Memory trick: Different apps, different rules: two policies are the tools.