Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium
An organization is configuring Azure AD Identity Protection and wants to ensure that users who sign in from anonymous IP addresses are always challenged for multi-factor authentication (MFA) and if they fail, their sign-in is blocked. However, they have a legitimate business requirement for a specific service account that must sign in from a known anonymous VPN endpoint for system maintenance. How can they configure the Anonymous IP address sign-in risk policy to accommodate this exception?
- AExclude the service account from all Identity Protection policies.
- BSet the Anonymous IP address policy to 'Report only' for the service account.
- CCreate a Conditional Access policy to allow sign-ins from the specific VPN for the service account.
- DConfigure a custom risk level for the service account for anonymous IP addresses.
Show answer & explanationAnswer & explanation
Correct answer: A. Exclude the service account from all Identity Protection policies.
To prevent a legitimate service account from being blocked by an Identity Protection policy, the most direct method is to exclude that specific account from the policy. This ensures that the policy's actions (MFA challenge, block) are not applied to the excluded entity.
Why the other options are wrong
- B. Setting to 'Report only' would still detect the risk and report it, potentially generating alerts, but wouldn't prevent the policy from being applied if it were later set to 'Enforce'. It doesn't solve the immediate blocking issue.
- C. While Conditional Access policies can be used, Identity Protection policies are specifically designed for risk detection. Excluding the account from Identity Protection is the more direct and appropriate method for managing policy exceptions within Identity Protection.
- D. Identity Protection policies do not allow configuring custom risk levels for specific accounts per risk type; risk levels are typically assigned by the system or configured at a policy level (e.g., low, medium, high).
Identity Protection Policy Exclusions
The ability to exclude specific users or groups from the scope of an Azure AD Identity Protection policy, allowing them to bypass the policy's enforcement actions.
- Used for legitimate exceptions (e.g., service accounts, break-glass accounts).
- Configured within each Identity Protection policy's settings.
- Essential for maintaining business continuity while enforcing security.
Memory trick: Exclude a few to protect the many.