Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium
A small business is setting up Azure AD for the first time. They want to ensure that all users have a baseline level of security enabled without requiring extensive configuration or licensing beyond Azure AD Free. They need to enforce MFA for administrative roles, block legacy authentication protocols, and require MFA for all users when they are deemed risky. Which Azure AD feature provides this out-of-the-box protection?
- AAzure AD Security Defaults
- BAzure AD Identity Protection policies
- CAzure AD Conditional Access policies
- DMicrosoft Defender for Identity
Show answer & explanationAnswer & explanation
Correct answer: A. Azure AD Security Defaults
Azure AD Security Defaults provide a free, baseline set of security policies including requiring MFA for administrative roles, blocking legacy authentication, and requiring MFA for risky sign-ins, which aligns perfectly with the company's needs without additional licensing.
Why the other options are wrong
- B. Identity Protection policies require Azure AD Premium P2, which is beyond the 'Azure AD Free' requirement.
- C. Conditional Access requires Azure AD Premium P1 license and offers more granular control, but Security Defaults is the out-of-the-box free option.
- D. Microsoft Defender for Identity is for on-premises AD threat detection and requires additional licensing.
Azure AD Security Defaults
A set of basic identity security policies that are pre-configured in Azure AD to provide a baseline level of security for all organizations, especially those using Azure AD Free. They help protect against common identity-related attacks.
- Included with all Azure AD licensing tiers, including Free.
- Enforces MFA for administrators.
- Blocks legacy authentication protocols.
- Requires MFA for risky sign-ins (limited scope).
Memory trick: Security Defaults: The free foundation for identity protection.