Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionEasy
A company is implementing Azure AD for their cloud-only environment. They want to ensure a baseline level of security for all users, including requiring MFA for administrative roles, blocking legacy authentication, and requiring MFA for all users for most sign-ins. They need a simple, pre-configured solution that can be enabled quickly without extensive policy configuration. Which feature should they enable?
- AAzure AD Conditional Access policies
- BAzure AD Identity Protection policies
- CPer-user MFA
- DAzure AD Security Defaults
Show answer & explanationAnswer & explanation
Correct answer: D. Azure AD Security Defaults
Azure AD Security Defaults provide a set of pre-configured, baseline security policies for all users, including MFA for admin roles, blocking legacy authentication, and requiring MFA for most sign-ins, making them ideal for quick implementation in cloud-only environments.
Why the other options are wrong
- A. Conditional Access offers granular control but requires manual configuration for each policy.
- B. Identity Protection focuses on risk detection and response, not baseline security for all users.
- C. Per-user MFA is a legacy method lacking dynamic policy enforcement and broad coverage.
Azure AD Security Defaults
Azure AD Security Defaults provide a basic level of security for all users in an Azure AD tenant, including MFA requirements and blocking legacy authentication, designed for organizations wanting easy-to-enable protection.
- Pre-configured, one-click enablement.
- Requires all users to register for MFA.
- Blocks legacy authentication protocols.
- Protects administrative roles.
Memory trick: Security defaults are the 'easy button' for baseline protection.