Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

An organization uses Azure AD for all user accounts. They want to implement a security policy that requires all users to register for multi-factor authentication (MFA) within 14 days of their account creation. If a user fails to register within this timeframe, they should be blocked from accessing resources until registration is complete. Which Azure AD Identity Protection policy should be configured to enforce this requirement?

  1. AMFA registration policy
  2. BSign-in risk policy
  3. CAnonymous IP address sign-in policy
  4. DUser risk policy
Show answer & explanation

Correct answer: A. MFA registration policy

The MFA registration policy in Azure AD Identity Protection is specifically designed to enforce MFA registration for users, including new users, ensuring compliance with security requirements for multi-factor authentication.

Why the other options are wrong

  • B. Sign-in risk policy detects risky sign-in attempts, not MFA registration.
  • C. Anonymous IP address sign-in policy blocks or challenges sign-ins from anonymous IPs, not MFA registration.
  • D. User risk policy detects compromised user accounts, not MFA registration.

Identity Protection MFA Registration Policy

An Azure AD Identity Protection policy that requires users to register for Azure AD Multi-Factor Authentication (MFA). It can be configured to target specific users and enforce registration, often used for new users.

  • Ensures users are enrolled in MFA.
  • Can target all users or specific groups.
  • Commonly used to onboard new users to MFA.

Memory trick: Protect identities by assessing risk and requiring MFA.

More Implement an identity management solution questions