Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium
A security administrator is reviewing user sign-in logs in Azure AD and notices several failed sign-in attempts for a specific user account originating from unusual geographic locations. The administrator suspects a potential brute-force attack or credential compromise. Which Azure AD feature provides automated protection against such threats by analyzing sign-in behavior and applying remediation actions?
- AAccess Reviews
- BCustom security attributes
- CIdentity Protection
- DPIM (Privileged Identity Management)
Show answer & explanationAnswer & explanation
Correct answer: C. Identity Protection
Azure AD Identity Protection is designed to detect, investigate, and remediate identity-based risks. It uses machine learning to analyze sign-in behavior and user activity, identifying suspicious actions like sign-ins from unfamiliar locations or impossible travel, and can automatically block or require MFA for risky sign-ins.
Why the other options are wrong
- A. Access Reviews help manage group memberships and application access periodically, not for automated sign-in risk assessment.
- B. Custom security attributes are used to categorize and secure directory objects, not for real-time sign-in risk detection.
- D. PIM focuses on managing, controlling, and monitoring access to important resources, not automated threat detection for sign-ins.
Azure AD Identity Protection
An Azure AD Premium P2 feature that detects, investigates, and remediates identity-based risks by analyzing sign-in and user behavior.
- Detects sign-in risks (e.g., impossible travel, unfamiliar locations).
- Detects user risks (e.g., leaked credentials).
- Can automatically enforce remediation actions like MFA or blocking.
Memory trick: Protect Identities, Prevent Intrusions.