Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium
A security administrator is reviewing sign-in logs in Azure AD and notices a significant number of failed sign-in attempts originating from unusual geographic locations for several user accounts. Some of these accounts also show signs of suspicious activity, such as sign-ins from infected devices. The administrator wants to automatically detect and respond to these types of risks. Which Azure AD feature should be configured?
- AAzure AD Audit Logs
- BAzure AD PIM
- CAzure AD Conditional Access policies
- DAzure AD Identity Protection
Show answer & explanationAnswer & explanation
Correct answer: D. Azure AD Identity Protection
Azure AD Identity Protection is designed to detect, investigate, and remediate identity-based risks. It uses machine learning to identify suspicious activities like sign-ins from unusual locations or infected devices and can automatically apply Conditional Access policies based on risk levels.
Why the other options are wrong
- A. Azure AD Audit Logs provide a record of activities but do not automatically detect or respond to risks; they are for review and forensics.
- B. Azure AD PIM manages privileged access and is not designed for general risk detection and response for all user sign-ins.
- C. Conditional Access policies can enforce actions based on conditions, but Identity Protection is the engine that identifies the *risk* (e.g., 'unusual location' or 'infected device') that Conditional Access can then act upon.
Azure AD Identity Protection
A security module in Azure AD that automates the detection, investigation, and remediation of identity-based risks.
- Detects real-time and offline risks (e.g., suspicious sign-ins, leaked credentials).
- Calculates user and sign-in risk levels.
- Can trigger Conditional Access policies for automated remediation (e.g., MFA, password reset).
Memory trick: Identity Protection detects risks, Conditional Access enforces rules.