Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

A company is implementing a new security policy that requires all users to register for multi-factor authentication (MFA) within 14 days of their account creation. If a user fails to register within this period, they should be blocked from signing in until MFA registration is completed. Which Azure AD Identity Protection policy should be configured to enforce this requirement?

  1. AUser risk policy
  2. BMFA registration policy
  3. CSign-in risk policy
  4. DConditional Access policy requiring MFA
Show answer & explanation

Correct answer: B. MFA registration policy

The Azure AD Identity Protection MFA registration policy is specifically designed to enforce MFA registration for users, allowing for a grace period and blocking access if registration is not completed within that time.

Why the other options are wrong

  • A. User risk policies detect compromised accounts, not enforce initial MFA registration.
  • C. Sign-in risk policies detect suspicious sign-in attempts, not enforce initial MFA registration.
  • D. While a Conditional Access policy can require MFA, it doesn't enforce the registration itself or provide a grace period like the Identity Protection MFA registration policy.

Identity Protection MFA Registration Policy

The MFA registration policy in Azure AD Identity Protection enforces that users register for Azure AD Multi-Factor Authentication, often with a configurable grace period.

  • Ensures new users register for MFA.
  • Can include a grace period.
  • Blocks access if registration is not completed.

Memory trick: MFA registration policy is the 'enrollment deadline' for security.

More Implement an identity management solution questions