Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium
A company is using Azure AD and wants to ensure that all user sign-ins are secure. They need to monitor and detect potential identity-based threats, such as impossible travel or sign-ins from unfamiliar locations. Additionally, they want to automatically respond to these risks by blocking or challenging suspicious sign-ins. Which Azure AD feature provides these capabilities?
- AAzure AD Conditional Access
- BAzure AD B2B collaboration
- CAzure AD Privileged Identity Management
- DAzure AD Identity Protection
Show answer & explanationAnswer & explanation
Correct answer: D. Azure AD Identity Protection
Azure AD Identity Protection detects identity-based risks like impossible travel and unfamiliar locations, and can configure policies to automatically respond to these risks, such as blocking access or requiring multi-factor authentication.
Why the other options are wrong
- A. Conditional Access enforces policies based on conditions, but Identity Protection is the engine that detects the 'risk' condition.
- B. B2B collaboration manages external user access; it does not provide risk detection for sign-ins.
- C. PIM focuses on managing and monitoring privileged access, not general sign-in risk detection.
Azure AD Identity Protection
A feature that enables organizations to detect, investigate, and remediate identity-based risks.
- Detects various types of risks: impossible travel, unfamiliar locations, leaked credentials, infected devices.
- Calculates a risk score for both users and sign-ins.
- Can be integrated with Conditional Access to enforce automated remediation (e.g., block, MFA).
Memory trick: Protect identities by spotting and stopping danger.