A security administrator needs to ensure that all administrative users in Azure Active Directory (Azure AD) who have highly privileged roles, such as Global Administrator or User Access Administrator, are required to use multi-factor authentication (MFA) every time they sign in, regardless of their location or device. This measure should also prevent them from using legacy authentication protocols. Which Azure AD feature is best suited to enforce these stringent security requirements?
- AAzure AD Security Defaults
- BAzure AD Identity Protection
- CAzure AD Privileged Identity Management (PIM)
- DAzure AD Conditional Access
Show answer & explanationAnswer & explanation
Correct answer: D. Azure AD Conditional Access
Azure AD Conditional Access policies provide the granular control needed to enforce MFA for specific highly privileged roles and block legacy authentication protocols. You can create a policy targeting these roles, requiring MFA for all sign-ins and explicitly blocking legacy authentication clients. While Security Defaults enforce MFA for all admins, Conditional Access offers more fine-grained control and the ability to block legacy authentication for specific roles.
Why the other options are wrong
- A. Azure AD Security Defaults enforce MFA for all administrative roles and block legacy authentication for all users, but Conditional Access offers more flexibility and granular control over which roles, users, and conditions apply.
- B. Azure AD Identity Protection detects identity-based risks and can trigger Conditional Access policies, but it's not the enforcement mechanism itself for continuous MFA or blocking legacy auth.
- C. Azure AD PIM manages just-in-time and just-enough access for privileged roles, which is complementary to Conditional Access for privileged accounts, but Conditional Access is the direct enforcer of MFA and legacy auth blocking.
Conditional Access for Privileged Roles
Azure AD Conditional Access policies are used to enforce stringent security requirements, such as mandatory MFA and blocking legacy authentication, for highly privileged administrative roles.
- Targets specific roles (e.g., Global Admin).
- Requires MFA for every sign-in.
- Blocks legacy authentication protocols.
Memory trick: Conditional Access: The bouncer for your VIP admins.