Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

An organization uses Azure AD for all user accounts. They want to implement a security policy that requires users to register for multi-factor authentication (MFA) within 14 days of their account creation. If a user fails to register within this period, they should be blocked from signing in until MFA registration is complete. Which Azure AD Identity Protection policy can achieve this requirement?

  1. ARisky sign-ins policy
  2. BMFA registration policy
  3. CRisky users policy
  4. DConditional Access policy for MFA
Show answer & explanation

Correct answer: B. MFA registration policy

The Azure AD Identity Protection MFA registration policy is specifically designed to enforce MFA registration for users, including requiring them to register within a specified timeframe and blocking access until registration is complete.

Why the other options are wrong

  • A. Risky sign-ins policy detects and responds to suspicious sign-in attempts, not initial MFA registration.
  • C. Risky users policy identifies users whose accounts have been compromised, not for enforcing initial MFA registration.
  • D. While Conditional Access can enforce MFA for access, it doesn't have the built-in 'register within X days' and 'block until registered' logic found in the Identity Protection MFA registration policy.

Identity Protection MFA Registration Policy

An Azure AD Identity Protection policy that enforces multi-factor authentication registration for users.

  • Can require users to register for MFA within a specified number of days.
  • Can block users from signing in until MFA registration is complete.
  • Helps improve overall security posture by ensuring MFA adoption.

Memory trick: Protection policies: MFA register, risky sign-ins, and risky users.

More Implement an identity management solution questions