Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium
A company uses Azure AD for all its cloud applications. They have recently implemented Azure AD Identity Protection and configured a 'User risk policy' to block users with a 'High' risk level. A user, John Doe, frequently travels internationally and uses a VPN. His sign-ins are often flagged as 'Anomalous sign-in location' and 'Unfamiliar sign-in properties' which contribute to a 'Medium' user risk score. However, a single sign-in from a known anonymous IP address has just increased his user risk score to 'High'. What will be the immediate impact on John Doe's access attempts based on the configured policy?
- AAn administrator will receive an alert and must manually intervene.
- BJohn Doe will be prompted for MFA on his next sign-in.
- CJohn Doe's account will be temporarily suspended.
- DJohn Doe's sign-in will be blocked immediately.
Show answer & explanationAnswer & explanation
Correct answer: D. John Doe's sign-in will be blocked immediately.
The 'User risk policy' is configured to block users with a 'High' risk level. As soon as John Doe's user risk score reaches 'High' due to the anonymous IP sign-in, any subsequent sign-in attempts will be blocked by the policy, preventing access.
Why the other options are wrong
- A. While an alert might be generated, the policy itself takes an immediate automated action (blocking) based on the risk level.
- B. MFA is typically prompted for 'Medium' risk or specific sign-in risk policies, not for blocking 'High' user risk.
- C. Account suspension is an option for remediation but not the immediate impact of a 'block' policy unless configured explicitly as such (which is not stated here).
Azure AD User Risk Policy
A Conditional Access policy that defines automated responses based on a user's accumulated risk score, which indicates the likelihood of a compromised identity.
- Applies to the user's identity, not individual sign-ins.
- Risk is aggregated over time from various detections.
- Common actions: Block access, Require password change, Require MFA.
Memory trick: Risk policies are like a 'security guard' at the door: high risk, no entry!