Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionHard
A company is implementing Azure AD Identity Protection. They have configured a policy to require MFA for all users when a high sign-in risk is detected. However, a specific group of service accounts needs to be excluded from this policy because they are used by automated processes that cannot perform MFA. How should the security administrator configure this exclusion while maintaining the policy for all other users?
- ACreate a Conditional Access policy that conflicts with the Identity Protection policy for the service accounts.
- BAdd the service accounts to a 'Bypass MFA' security group in Azure AD.
- CDisable the Identity Protection policy for all users and rely on a separate Conditional Access policy for MFA.
- DConfigure the 'Exclusions' setting within the Identity Protection sign-in risk policy to include the service accounts group.
Show answer & explanationAnswer & explanation
Correct answer: D. Configure the 'Exclusions' setting within the Identity Protection sign-in risk policy to include the service accounts group.
Azure AD Identity Protection policies, like the sign-in risk policy, include an 'Exclusions' setting. This allows administrators to specify users or groups that should not be subject to the policy, which is ideal for service accounts or other exceptions.
Why the other options are wrong
- A. Creating conflicting policies is generally poor practice and can lead to unpredictable behavior; direct exclusion is preferred.
- B. There is no built-in 'Bypass MFA' security group functionality that directly interacts with Identity Protection policies in this manner.
- C. Disabling the policy for all users would negate its purpose for the majority of users and is not a targeted exclusion.
Identity Protection Policy Exclusions
A setting within Azure AD Identity Protection policies that allows administrators to specify users or groups who should not be subject to the conditions or actions of that particular policy. This is used for exceptions like service accounts or specific test users.
- Available for User Risk and Sign-in Risk policies.
- Allows for fine-grained control over policy application.
- Ensures automated processes or specific users are not disrupted.
Memory trick: Protection for most, but exceptions for the few.