Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

A company uses Azure AD for identity management and has implemented Conditional Access policies. They want to ensure that all users accessing highly sensitive applications are prompted for multi-factor authentication (MFA), regardless of their location or device compliance. However, they also want to allow a specific group of service accounts to bypass MFA when accessing these applications from a trusted network location. How should they configure this?

  1. ACreate a Conditional Access policy requiring MFA for the sensitive applications, and configure a separate policy to grant the service accounts access without MFA.
  2. BCreate a Conditional Access policy requiring MFA for the sensitive applications, and use an exclusion in the 'Conditions' tab for the IP range and the service accounts group.
  3. CEnable Security Defaults for all users, and then create an MFA exclusion policy for the service accounts.
  4. DCreate a Conditional Access policy requiring MFA for the sensitive applications, excluding the service accounts group from the policy.
Show answer & explanation

Correct answer: B. Create a Conditional Access policy requiring MFA for the sensitive applications, and use an exclusion in the 'Conditions' tab for the IP range and the service accounts group.

To meet both requirements, a Conditional Access policy should be created targeting the sensitive applications and requiring MFA. Within this policy, the service accounts group should be excluded under the 'Users and groups' assignment, and the trusted network location should be excluded under 'Conditions > Locations' for these service accounts, allowing them to bypass MFA from that specific network.

Why the other options are wrong

  • A. Conditional Access policies are evaluated in a 'grant or block' manner, not by granting access without MFA via a separate policy if MFA is required by another.
  • C. Security Defaults are a baseline and cannot be granularly configured with exclusions for specific groups and trusted networks in this manner. It's an all-or-nothing approach for most users.
  • D. Excluding the service accounts group from the entire policy would allow them to bypass MFA from ANY location, not just trusted ones.

Conditional Access Policy Exclusions

Conditional Access policies can include exclusions for users, groups, cloud apps, or conditions (like locations or device states) to refine policy application.

  • Exclusions always 'win' over inclusions.
  • Can be specified for users/groups, cloud apps, and conditions.
  • Allows fine-tuning access controls for specific scenarios.

Memory trick: Conditions come first, then controls, but exclusions always win the race.

More Implement an identity management solution questions