Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionEasy

A company uses Azure AD as its primary identity provider. They need to ensure that all users, including guest users, are prompted for multi-factor authentication (MFA) when accessing sensitive applications, regardless of their location or device. What is the most efficient way to achieve this requirement?

  1. AEnable security defaults in Azure AD.
  2. BUse Identity Protection sign-in risk policy to block access for risky sign-ins.
  3. CImplement per-user MFA for all users in Azure AD.
  4. DConfigure an Azure AD Conditional Access policy requiring MFA for sensitive applications.
Show answer & explanation

Correct answer: D. Configure an Azure AD Conditional Access policy requiring MFA for sensitive applications.

Conditional Access policies are the most flexible and scalable way to enforce MFA for specific applications, user groups, and conditions. Security defaults enforce MFA for all sign-ins, which might be too broad for sensitive applications only.

Why the other options are wrong

  • A. Security defaults apply MFA to all sign-ins, not just sensitive applications, and lack granularity.
  • B. Identity Protection policies detect risk but do not directly enforce MFA for all access to sensitive applications; Conditional Access acts on these signals.
  • C. Per-user MFA is a legacy method and does not offer the granular control or dynamic enforcement of Conditional Access.

Azure AD Conditional Access

Azure AD Conditional Access allows organizations to enforce policies for accessing resources based on conditions like user, location, device, and application, enhancing security.

  • Enforces access policies based on specific conditions.
  • Can require MFA, block access, or enforce device compliance.
  • Centralized control over access to cloud apps.

Memory trick: Conditioned access is like a traffic light for your apps.

More Implement an identity management solution questions