Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionHard
A company has implemented Azure AD Identity Protection and configured a policy to block sign-ins from 'Anonymous IP addresses'. Recently, legitimate users have reported being blocked when signing in from public Wi-Fi networks that utilize VPNs or proxies, which are sometimes flagged as anonymous. The security team wants to allow these legitimate sign-ins while still protecting against truly anonymous or malicious sources. What is the most effective adjustment to the policy?
- AConfigure trusted IP addresses for known VPN/proxy ranges.
- BChange the policy action from 'Block access' to 'Require multi-factor authentication'.
- CExclude all users from the 'Anonymous IP addresses' policy.
- DDisable the 'Anonymous IP addresses' policy entirely.
Show answer & explanationAnswer & explanation
Correct answer: B. Change the policy action from 'Block access' to 'Require multi-factor authentication'.
Changing the policy action from 'Block access' to 'Require multi-factor authentication' for sign-ins from anonymous IP addresses allows legitimate users to access resources after proving their identity with MFA, while still adding a layer of security against potentially risky sign-ins.
Why the other options are wrong
- A. Configuring trusted IP addresses is useful for *known corporate networks*, but public Wi-Fi VPN/proxy ranges are dynamic and cannot be reliably added as trusted IPs, making this impractical for the scenario described.
- C. Excluding all users from the policy is equivalent to disabling it and compromises security.
- D. Disabling the policy entirely removes a crucial layer of protection against potentially malicious anonymous sign-ins.
Identity Protection Anonymous IP Policy Actions
Actions that can be configured in Azure AD Identity Protection for sign-ins detected from anonymous IP addresses.
- Options typically include 'Block access' or 'Require multi-factor authentication'.
- MFA provides a balance between security and user experience for potentially legitimate but risky sign-ins.
- Helps mitigate risks associated with Tor browsers, anonymous VPNs, and other anonymizing technologies.
Memory trick: Risk Remediation: Block, MFA, Reset, or Ignore actions.