Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionEasy
A small startup is implementing Azure AD for their cloud-only environment. They want to ensure a baseline level of security for all user accounts without requiring extensive configuration or licensing beyond the free Azure AD tier. They are particularly concerned about protecting against common identity attacks and ensuring all users register for multi-factor authentication (MFA). Which feature should they enable?
- APremium P1 features
- BSecurity Defaults
- CConditional Access Policies
- DIdentity Protection Policies
Show answer & explanationAnswer & explanation
Correct answer: B. Security Defaults
Security Defaults provide a basic level of security for all Azure AD tenants, including mandatory MFA registration and enforcement, blocking legacy authentication, and protecting privileged accounts, all available in the free tier.
Why the other options are wrong
- A. Premium P1 features include Conditional Access and other advanced capabilities, but the question specifies 'free Azure AD tier'.
- C. Conditional Access Policies offer granular control but require Azure AD Premium P1 or P2 licenses.
- D. Identity Protection Policies provide advanced detection and remediation of identity-based risks but require Azure AD Premium P2 licenses.
Azure AD Security Defaults
A set of pre-configured identity security settings in Azure AD that provide a baseline level of protection for all organizations, available for free.
- Mandatory MFA registration for all users.
- Requires MFA for risky sign-ins (admin roles).
- Blocks legacy authentication protocols.
- Protects privileged activities.
Memory trick: Default to secure, no extra cost, no fuss.