Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionHard

A company has implemented Azure AD Identity Protection and configured a policy to block sign-ins when an anonymous IP address is detected. They observe that some legitimate users are being blocked when connecting from certain public Wi-Fi networks or VPN services that are misidentified as anonymous. The security team wants to allow these specific legitimate sources while still blocking truly anonymous (e.g., Tor exit nodes) or malicious IP addresses. How should they refine the policy?

  1. ADisable the anonymous IP address sign-in policy entirely.
  2. BConfigure trusted IP addresses or named locations in Azure AD and update the Conditional Access policy that enforces the Identity Protection policy.
  3. CCreate a new Identity Protection policy with a lower risk threshold for anonymous IP addresses.
  4. DChange the policy action from 'Block access' to 'Require multi-factor authentication'.
Show answer & explanation

Correct answer: B. Configure trusted IP addresses or named locations in Azure AD and update the Conditional Access policy that enforces the Identity Protection policy.

To allow legitimate sources while maintaining protection, 'Trusted IPs' or 'Named locations' should be configured in Azure AD. These are then used in Conditional Access policies to exempt traffic originating from these known safe locations from certain requirements, including those imposed by Identity Protection's anonymous IP detection.

Why the other options are wrong

  • A. Disabling the policy removes all protection against anonymous IPs, which is not the goal.
  • C. Identity Protection's anonymous IP detection is a binary 'detected' or 'not detected' rather than a configurable risk threshold; this option is not applicable.
  • D. Requiring MFA is a softer action but doesn't differentiate between legitimate and malicious anonymous IPs.

Identity Protection Anonymous IP Policy Actions

An Azure AD Identity Protection policy that detects sign-ins from IP addresses associated with anonymity tools (e.g., Tor browsers, anonymous VPNs). Actions can be configured to block or challenge these sign-ins.

  • Helps prevent credential stuffing and identity compromise.
  • Can be configured to block or require MFA.
  • Can be refined using Conditional Access and Named Locations for legitimate exceptions.

Memory trick: Block the ghosts, but let trusted friends pass.

More Implement an identity management solution questions