Microsoft Certified: Azure Security Engineer AssociateManage identity and accessEasy

A company is implementing a new policy that requires all users accessing sensitive applications to use multi-factor authentication (MFA) regardless of their location or device. They want to enforce this policy using Azure Active Directory. Which feature should they configure?

  1. AAzure AD Identity Protection
  2. BAzure AD Conditional Access
  3. CAzure AD B2B Collaboration
  4. DAzure AD Privileged Identity Management
Show answer & explanation

Correct answer: B. Azure AD Conditional Access

Azure AD Conditional Access is the primary tool in Azure AD for enforcing policies that require specific conditions (like MFA) to access resources. It allows administrators to define 'if-then' statements to control access.

Why the other options are wrong

  • A. Azure AD Identity Protection focuses on detecting and remediating identity-based risks, not enforcing access policies directly.
  • C. Azure AD B2B Collaboration is used for inviting guest users from other organizations, not for enforcing MFA for internal users.
  • D. Azure AD Privileged Identity Management (PIM) manages, controls, and monitors access to important resources, primarily for just-in-time access, not general MFA enforcement.

Azure AD Conditional Access

A feature of Azure Active Directory that enables organizations to enforce policies for accessing resources based on specific conditions.

  • Enforces 'if-then' statements for access.
  • Commonly used for MFA, device compliance, location-based access.
  • Requires Azure AD Premium P1 or P2 license.

Memory trick: Conditional Access is the bouncer checking your credentials at the club door.

More Manage identity and access questions