Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium
A global enterprise uses Azure AD for identity management. Due to regulatory compliance, all employees accessing sensitive applications must use a FIDO2 security key as their second factor of authentication. However, some legacy applications only support username/password. The security team needs to implement a solution that enforces FIDO2 for sensitive applications while allowing employees to use other MFA methods for legacy applications, all managed within Azure AD. Which Azure AD feature should be configured to achieve this granular control?
- AAzure AD Identity Protection policies
- BAzure AD authentication methods policy
- CAzure AD Conditional Access policies
- DAzure AD Multi-Factor Authentication (MFA) settings per user
Show answer & explanationAnswer & explanation
Correct answer: C. Azure AD Conditional Access policies
Azure AD Conditional Access policies allow for granular control over access to applications based on various conditions, including authentication strength. By defining a policy that targets sensitive applications and requires a FIDO2 security key as an authentication strength, and separate policies for legacy applications with broader MFA requirements, the company can meet its compliance needs.
Why the other options are wrong
- A. Identity Protection policies primarily detect and remediate identity-based risks, not enforce specific authentication methods per application.
- B. The authentication methods policy defines which methods are available to users, but Conditional Access enforces *when* and *where* they are required.
- D. MFA settings per user apply globally to a user, not to specific applications, making it unsuitable for granular application-based enforcement.
Conditional Access Authentication Strength
A feature within Azure AD Conditional Access that allows administrators to specify the strength of authentication required for specific resources or scenarios.
- Enforces specific MFA methods (e.g., FIDO2, Windows Hello for Business).
- Provides granular control over authentication requirements.
- Integrates with Conditional Access policies to secure access.
Memory trick: Conditions dictate the keys to every app's door.