Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

A company is implementing Azure AD Identity Protection. They have configured a user risk policy set to 'Medium' and a sign-in risk policy set to 'High'. Both policies are configured to block access. A user attempts to sign in, and Identity Protection detects both a 'Medium' user risk and a 'Medium' sign-in risk for this specific attempt. What will be the outcome for this sign-in attempt?

  1. AAccess will be blocked due to the sign-in risk policy.
  2. BAccess will be blocked due to the user risk policy.
  3. CAccess will be granted, as neither policy's blocking threshold was met.
  4. DAccess will be granted, but the user will be prompted to reset their password.
Show answer & explanation

Correct answer: B. Access will be blocked due to the user risk policy.

The user risk policy is set to block 'Medium' risk. Since the user has a 'Medium' user risk, this policy's condition is met, leading to access being blocked, regardless of the sign-in risk policy's threshold.

Why the other options are wrong

  • A. The sign-in risk policy requires 'High' risk to block, but the detected sign-in risk was 'Medium', so this specific policy's blocking condition was not met.
  • C. The user risk policy's condition for blocking ('Medium' risk) was indeed met.
  • D. Password reset is an action, but blocking is the primary outcome when policies are set to block.

Identity Protection Policy Evaluation

Azure AD Identity Protection evaluates user risk and sign-in risk policies independently. If any policy configured to block access has its conditions met, access is blocked.

  • Two main policy types: User risk and Sign-in risk.
  • Policies are evaluated concurrently.
  • Blocking takes precedence if any applicable policy's conditions are met.

Memory trick: Risk policies are like two separate gates; if either one is closed, you don't get through.

More Implement an identity management solution questions