Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionEasy

A company is implementing Azure AD for their cloud-only environment. They want to ensure a baseline level of security for all users, including requiring MFA for administrative roles, blocking legacy authentication, and requiring MFA for all users for most sign-ins. They need a simple, pre-configured solution that can be enabled quickly without extensive policy configuration. Which feature should they enable?

  1. AAzure AD Conditional Access policies
  2. BAzure AD Identity Protection policies
  3. CPer-user MFA
  4. DAzure AD Security Defaults
Show answer & explanation

Correct answer: D. Azure AD Security Defaults

Azure AD Security Defaults provide a set of pre-configured, baseline security policies for all users, including MFA for admin roles, blocking legacy authentication, and requiring MFA for most sign-ins, making them ideal for quick implementation in cloud-only environments.

Why the other options are wrong

  • A. Conditional Access offers granular control but requires manual configuration for each policy.
  • B. Identity Protection focuses on risk detection and response, not baseline security for all users.
  • C. Per-user MFA is a legacy method lacking dynamic policy enforcement and broad coverage.

Azure AD Security Defaults

Azure AD Security Defaults provide a basic level of security for all users in an Azure AD tenant, including MFA requirements and blocking legacy authentication, designed for organizations wanting easy-to-enable protection.

  • Pre-configured, one-click enablement.
  • Requires all users to register for MFA.
  • Blocks legacy authentication protocols.
  • Protects administrative roles.

Memory trick: Security defaults are the 'easy button' for baseline protection.

More Implement an identity management solution questions