A large organization uses Azure AD and has delegated the management of user accounts to several department-level administrators. They want to ensure that these department administrators, when performing sensitive actions like resetting passwords for their users, are always prompted for multi-factor authentication (MFA), even if their regular sign-in session did not require it. Which Conditional Access feature should be used?
- ASign-in frequency
- BUser actions condition
- CSession controls for application-enforced restrictions
- DAuthentication strengths
Show answer & explanationAnswer & explanation
Correct answer: B. User actions condition
The 'User actions' condition in Conditional Access allows you to target specific sensitive actions within Azure AD (like 'Register security information' or 'Register or join devices') and apply policies to them. While password reset isn't a direct 'user action' condition, the most granular way to apply MFA to specific administrative actions is often through a combination of targeting 'Admin roles' and then applying specific MFA controls within that policy. However, for a direct 'action' based prompt, 'User actions' is the closest concept if the action was exposed. Given the options, 'User actions' would be the most granular approach to trigger MFA for specific administrative *tasks* if those were exposed as actions, which is the spirit of the question. For administrative roles performing actions, often a policy targeting the role itself with MFA is used, but 'User actions' aims for the granularity of the *action*.
Why the other options are wrong
- A. Sign-in frequency controls how often users are prompted to re-authenticate, not specific actions within a session.
- C. Session controls for application-enforced restrictions allow apps to enforce controls, not force MFA for specific Azure AD administrative actions.
- D. Authentication strengths define the types of MFA methods allowed, not when MFA is prompted for specific administrative actions.
Conditional Access: User Actions Condition
A condition type in Azure AD Conditional Access that allows policies to be applied specifically when users perform certain sensitive actions within Azure AD.
- Targets specific sensitive actions (e.g., registering security info).
- Can enforce MFA or other controls for these actions.
- Provides granular control over sensitive operations.
Memory trick: User Actions is like a mini-MFA checkpoint for just the 'extra sensitive' buttons.