Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionEasy

A small business is setting up Azure AD for the first time. They want to ensure that all users are prompted to set up security info (MFA methods) when they first sign in to any Azure AD-integrated application. This should be a mandatory, one-time setup for all users. Which feature should be enabled?

  1. AAzure AD Managed Identities
  2. BSecurity Defaults
  3. CConditional Access policies
  4. DAzure AD Identity Protection
Show answer & explanation

Correct answer: B. Security Defaults

Security Defaults in Azure AD provide a baseline set of security policies, including requiring all users to register for MFA. This ensures that users are prompted for MFA setup upon their first interactive sign-in.

Why the other options are wrong

  • A. Managed Identities are for Azure resources, not human users.
  • C. Conditional Access policies offer granular control but require an Azure AD P1 license and are more complex to configure than Security Defaults for this baseline need.
  • D. Azure AD Identity Protection detects and remediates risks, and while it has an MFA registration policy, Security Defaults is the simpler, free option for initial universal MFA enforcement.

Azure AD Security Defaults

A set of pre-configured identity security settings in Azure AD designed to help protect organizations from common attacks.

  • Included with all Azure AD licenses (Free, P1, P2).
  • Enforces MFA registration and challenge for all users.
  • Requires administrators to perform MFA, blocks legacy authentication protocols.

Memory trick: Initial Security: Defaults are simple, Conditional is custom, Protection is for risk.

More Implement an identity management solution questions