Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard

A company is implementing a new policy where all users must re-authenticate every 8 hours, even if their session is still active, to access highly sensitive applications. This policy needs to apply regardless of the user's location or device. Which Azure AD feature, when configured with a specific setting, can enforce this re-authentication frequency?

  1. AAzure AD Identity Protection risk policies
  2. BAzure AD Privileged Identity Management (PIM) role settings
  3. CAzure AD Conditional Access session controls
  4. DAzure AD Multi-Factor Authentication (MFA) settings
Show answer & explanation

Correct answer: C. Azure AD Conditional Access session controls

Azure AD Conditional Access allows for granular control over user sessions. Specifically, the 'Sign-in frequency' session control can be configured to require users to re-authenticate after a set period (e.g., 8 hours), regardless of other conditions, thus enforcing the re-authentication policy for sensitive applications.

Why the other options are wrong

  • A. Identity Protection risk policies enforce actions based on detected risks, not a fixed re-authentication interval.
  • B. PIM role settings apply to the activation duration of privileged roles, not general user session re-authentication.
  • D. MFA settings configure how MFA works, not the frequency of re-authentication for active sessions.

Conditional Access Session Controls (Sign-in Frequency)

A Conditional Access control that dictates how often users are required to re-authenticate, even within an active session.

  • Configurable in hours or days.
  • Applies to specific applications or users.
  • Enhances security for sensitive resources.

Memory trick: Conditional Session: Control Re-Auth Time.

More Manage identity and access questions