Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium

A large organization uses Azure AD to manage its identities. They have a policy that all users must use Multi-Factor Authentication (MFA) for cloud application access, but they want to allow exceptions for known, trusted network locations (e.g., corporate offices) to improve user experience. Which Azure AD feature provides the capability to define and enforce this policy?

  1. AAzure AD Conditional Access
  2. BAzure AD Privileged Identity Management (PIM)
  3. CAzure AD Identity Protection
  4. DAzure AD Multi-Factor Authentication (MFA) settings
Show answer & explanation

Correct answer: A. Azure AD Conditional Access

Azure AD Conditional Access allows administrators to create policies that enforce specific access controls based on various conditions, including user location. By defining trusted network locations (named locations) and configuring a Conditional Access policy, MFA can be required for all locations EXCEPT the trusted ones, thus meeting the requirement.

Why the other options are wrong

  • B. PIM manages just-in-time access for privileged roles, not general MFA policy enforcement based on location.
  • C. Identity Protection focuses on risk detection and remediation, not on defining and enforcing access policies based on network location.
  • D. Global MFA settings apply broadly; Conditional Access provides the granularity to create exceptions based on network location.

Azure AD Conditional Access (Location-based)

Enforces access policies based on the user's network location, allowing for granular control like MFA exemptions.

  • Uses 'Named locations' to define trusted IPs.
  • Allows 'Exclude' trusted locations from policies.
  • Requires Azure AD Premium P1.

Memory trick: Conditional Location: Control MFA by Where You Are.

More Manage identity and access questions