Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

A company is implementing a new policy in Azure AD Identity Protection to detect sign-ins from anonymous IP addresses. They want to configure the policy to automatically block any sign-in attempt from an anonymous IP address. However, they are concerned about potential false positives and want to monitor the policy's impact before enforcing it. Which action should they initially configure for the Anonymous IP address sign-in risk policy?

  1. AReport only
  2. BAllow access
  3. CBlock access
  4. DRequire multi-factor authentication
Show answer & explanation

Correct answer: A. Report only

The 'Report only' action in Identity Protection policies allows organizations to monitor the impact of a policy without enforcing any actions. This is crucial for evaluating potential false positives and understanding the policy's effect before full enforcement.

Why the other options are wrong

  • B. Allow access would not detect or act on the anonymous IP sign-in, failing to meet the monitoring requirement.
  • C. Block access is an enforcement action and would immediately block users, which goes against the requirement to monitor for false positives first.
  • D. Requiring MFA is an enforcement action, which would not allow monitoring for false positives without impacting users.

Identity Protection Report Only Mode

A configuration option for Azure AD Identity Protection policies that allows administrators to evaluate the impact of a policy without enforcing any actions, by simply logging detected risks.

  • Enables monitoring of policy effectiveness.
  • Helps identify potential false positives.
  • Crucial step before full policy enforcement.

Memory trick: Report Only: Review before you React.

More Implement an identity management solution questions