Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium
An organization uses Azure AD for all user accounts. They want to implement a security policy that requires users to register for multi-factor authentication (MFA) within 14 days of their account creation. If a user fails to register within this period, they should be blocked from signing in until MFA registration is complete. Which Azure AD Identity Protection policy can achieve this requirement?
- ARisky sign-ins policy
- BMFA registration policy
- CRisky users policy
- DConditional Access policy for MFA
Show answer & explanationAnswer & explanation
Correct answer: B. MFA registration policy
The Azure AD Identity Protection MFA registration policy is specifically designed to enforce MFA registration for users, including requiring them to register within a specified timeframe and blocking access until registration is complete.
Why the other options are wrong
- A. Risky sign-ins policy detects and responds to suspicious sign-in attempts, not initial MFA registration.
- C. Risky users policy identifies users whose accounts have been compromised, not for enforcing initial MFA registration.
- D. While Conditional Access can enforce MFA for access, it doesn't have the built-in 'register within X days' and 'block until registered' logic found in the Identity Protection MFA registration policy.
Identity Protection MFA Registration Policy
An Azure AD Identity Protection policy that enforces multi-factor authentication registration for users.
- Can require users to register for MFA within a specified number of days.
- Can block users from signing in until MFA registration is complete.
- Helps improve overall security posture by ensuring MFA adoption.
Memory trick: Protection policies: MFA register, risky sign-ins, and risky users.