Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard

A global company uses Azure Active Directory (Azure AD) and has several business-critical applications. They want to ensure that users accessing these applications from untrusted locations (e.g., outside corporate network, high-risk countries) are prompted for multi-factor authentication (MFA), even if they have previously satisfied MFA within the same session. Which Azure AD feature and configuration combination should be used?

  1. AAzure AD Conditional Access with a 'Sign-in risk policy'
  2. BAzure AD Privileged Identity Management (PIM) with 'Require MFA on activation'
  3. CAzure AD Conditional Access with a 'Require MFA' grant control and session control for 'Sign-in frequency'
  4. DAzure AD Identity Protection with a 'User risk policy'
Show answer & explanation

Correct answer: C. Azure AD Conditional Access with a 'Require MFA' grant control and session control for 'Sign-in frequency'

Azure AD Conditional Access is the correct feature. To enforce MFA from untrusted locations and ensure it's prompted even if previously satisfied, you need to configure a policy that 'Requires MFA' and also sets the 'Sign-in frequency' session control. This allows re-prompting for MFA based on conditions or time, overriding previous MFA satisfaction.

Why the other options are wrong

  • A. A sign-in risk policy from Conditional Access can detect risky sign-ins (e.g., untrusted locations) and require MFA. However, it might not re-prompt if MFA was already satisfied in the same session without also configuring sign-in frequency.
  • B. PIM focuses on just-in-time access for privileged roles and requiring MFA upon activation, not general user access to business applications from specific locations.
  • D. Identity Protection's user risk policy triggers MFA/block based on the *user's* overall risk, not specifically for untrusted locations or overriding session MFA.

Conditional Access Sign-in Frequency

Conditional Access 'Sign-in frequency' is a session control that determines how often users are required to re-authenticate, including re-prompting for MFA, even within an active session.

  • Configured within Azure AD Conditional Access policies.
  • Can be set in hours, days, or 'every time'.
  • Ensures re-authentication even if MFA was previously satisfied, based on defined interval.

Memory trick: Conditional Access with Sign-in Frequency is the bouncer that re-checks everyone from suspicious areas.

More Manage Azure identities and governance questions