Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionHard
A company is implementing Azure AD Identity Protection. They have configured a policy to require multi-factor authentication (MFA) for users with a 'High' risk level. A user, User1, consistently signs in from unusual locations and devices, triggering a 'High' risk level. However, User1 is a critical executive and cannot tolerate MFA prompts due to an existing accessibility issue. The security team needs to ensure User1 can still sign in without MFA, even with a 'High' risk, while keeping the policy active for all other high-risk users. What is the most appropriate way to achieve this?
- AExclude User1 from the Identity Protection 'High' risk policy.
- BCreate a Conditional Access policy to exclude User1 from MFA.
- CDisable the Identity Protection 'High' risk policy for all users.
- DSet User1's risk level to 'Low' manually in Identity Protection.
Show answer & explanationAnswer & explanation
Correct answer: A. Exclude User1 from the Identity Protection 'High' risk policy.
Excluding User1 from the specific Identity Protection policy is the most granular and appropriate way to bypass the MFA requirement for that user while keeping the policy active for all other high-risk users. This directly addresses the policy's impact on User1.
Why the other options are wrong
- B. While a Conditional Access policy could exclude User1 from MFA, Identity Protection policies are evaluated first. The most direct and clean way to manage exceptions for Identity Protection policies is within the policy's exclusion settings itself.
- C. Disabling the policy for all users undermines the security posture for the entire organization.
- D. Manually setting User1's risk to 'Low' is not sustainable, as Identity Protection will re-evaluate and likely set it back to 'High' due to actual risky behavior.
Identity Protection Policy Exclusions
Allows specific users or groups to be excluded from the enforcement of an Azure AD Identity Protection policy.
- Provides granular control for managing exceptions to security policies.
- Useful for service accounts, break-glass accounts, or users with specific accessibility needs.
- Should be used sparingly and with careful consideration of security implications.
Memory trick: Policy Management: Create, Exclude, Report, and Monitor carefully.