Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionHard

A company has implemented Azure AD Identity Protection and configured a policy to block sign-ins from 'Anonymous IP addresses'. Recently, legitimate users have reported being blocked when signing in from public Wi-Fi networks that utilize VPNs or proxies, which are sometimes flagged as anonymous. The security team wants to allow these legitimate sign-ins while still protecting against truly anonymous or malicious sources. What is the most effective adjustment to the policy?

  1. AConfigure trusted IP addresses for known VPN/proxy ranges.
  2. BChange the policy action from 'Block access' to 'Require multi-factor authentication'.
  3. CExclude all users from the 'Anonymous IP addresses' policy.
  4. DDisable the 'Anonymous IP addresses' policy entirely.
Show answer & explanation

Correct answer: B. Change the policy action from 'Block access' to 'Require multi-factor authentication'.

Changing the policy action from 'Block access' to 'Require multi-factor authentication' for sign-ins from anonymous IP addresses allows legitimate users to access resources after proving their identity with MFA, while still adding a layer of security against potentially risky sign-ins.

Why the other options are wrong

  • A. Configuring trusted IP addresses is useful for *known corporate networks*, but public Wi-Fi VPN/proxy ranges are dynamic and cannot be reliably added as trusted IPs, making this impractical for the scenario described.
  • C. Excluding all users from the policy is equivalent to disabling it and compromises security.
  • D. Disabling the policy entirely removes a crucial layer of protection against potentially malicious anonymous sign-ins.

Identity Protection Anonymous IP Policy Actions

Actions that can be configured in Azure AD Identity Protection for sign-ins detected from anonymous IP addresses.

  • Options typically include 'Block access' or 'Require multi-factor authentication'.
  • MFA provides a balance between security and user experience for potentially legitimate but risky sign-ins.
  • Helps mitigate risks associated with Tor browsers, anonymous VPNs, and other anonymizing technologies.

Memory trick: Risk Remediation: Block, MFA, Reset, or Ignore actions.

More Implement an identity management solution questions