Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium
A company is implementing Azure AD Identity Protection. They have configured a user risk policy set to 'Medium' and a sign-in risk policy set to 'High'. Both policies are configured to block access. A user attempts to sign in, and Identity Protection detects both a 'Medium' user risk and a 'Medium' sign-in risk for this specific attempt. What will be the outcome for this sign-in attempt?
- AAccess will be blocked due to the sign-in risk policy.
- BAccess will be blocked due to the user risk policy.
- CAccess will be granted, as neither policy's blocking threshold was met.
- DAccess will be granted, but the user will be prompted to reset their password.
Show answer & explanationAnswer & explanation
Correct answer: B. Access will be blocked due to the user risk policy.
The user risk policy is set to block 'Medium' risk. Since the user has a 'Medium' user risk, this policy's condition is met, leading to access being blocked, regardless of the sign-in risk policy's threshold.
Why the other options are wrong
- A. The sign-in risk policy requires 'High' risk to block, but the detected sign-in risk was 'Medium', so this specific policy's blocking condition was not met.
- C. The user risk policy's condition for blocking ('Medium' risk) was indeed met.
- D. Password reset is an action, but blocking is the primary outcome when policies are set to block.
Identity Protection Policy Evaluation
Azure AD Identity Protection evaluates user risk and sign-in risk policies independently. If any policy configured to block access has its conditions met, access is blocked.
- Two main policy types: User risk and Sign-in risk.
- Policies are evaluated concurrently.
- Blocking takes precedence if any applicable policy's conditions are met.
Memory trick: Risk policies are like two separate gates; if either one is closed, you don't get through.