A global company uses Azure Active Directory (Azure AD) and has several business-critical applications. They want to ensure that users accessing these applications from untrusted locations (e.g., outside corporate network, high-risk countries) are prompted for multi-factor authentication (MFA), even if they have previously satisfied MFA within the same session. Which Azure AD feature and configuration combination should be used?
- AAzure AD Conditional Access with a 'Sign-in risk policy'
- BAzure AD Privileged Identity Management (PIM) with 'Require MFA on activation'
- CAzure AD Conditional Access with a 'Require MFA' grant control and session control for 'Sign-in frequency'
- DAzure AD Identity Protection with a 'User risk policy'
Show answer & explanationAnswer & explanation
Correct answer: C. Azure AD Conditional Access with a 'Require MFA' grant control and session control for 'Sign-in frequency'
Azure AD Conditional Access is the correct feature. To enforce MFA from untrusted locations and ensure it's prompted even if previously satisfied, you need to configure a policy that 'Requires MFA' and also sets the 'Sign-in frequency' session control. This allows re-prompting for MFA based on conditions or time, overriding previous MFA satisfaction.
Why the other options are wrong
- A. A sign-in risk policy from Conditional Access can detect risky sign-ins (e.g., untrusted locations) and require MFA. However, it might not re-prompt if MFA was already satisfied in the same session without also configuring sign-in frequency.
- B. PIM focuses on just-in-time access for privileged roles and requiring MFA upon activation, not general user access to business applications from specific locations.
- D. Identity Protection's user risk policy triggers MFA/block based on the *user's* overall risk, not specifically for untrusted locations or overriding session MFA.
Conditional Access Sign-in Frequency
Conditional Access 'Sign-in frequency' is a session control that determines how often users are required to re-authenticate, including re-prompting for MFA, even within an active session.
- Configured within Azure AD Conditional Access policies.
- Can be set in hours, days, or 'every time'.
- Ensures re-authentication even if MFA was previously satisfied, based on defined interval.
Memory trick: Conditional Access with Sign-in Frequency is the bouncer that re-checks everyone from suspicious areas.