Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard

A financial institution uses Azure AD for its workforce. They have identified a critical business application that processes highly sensitive customer data. Access to this application must be restricted to specific IP ranges representing corporate offices and approved VPN endpoints. Additionally, users accessing this application must always use Multi-Factor Authentication (MFA), even if they have recently completed MFA for another application. Which combination of Azure AD features should be implemented to meet these requirements?

  1. AConditional Access Policies with location condition and persistent browser sessions
  2. BAzure AD Identity Protection and Conditional Access with MFA registration policy
  3. CConditional Access Policies with location condition and sign-in frequency session control
  4. DAzure AD Privileged Identity Management (PIM) and Conditional Access with authentication strength
Show answer & explanation

Correct answer: C. Conditional Access Policies with location condition and sign-in frequency session control

Conditional Access Policies with a location condition can restrict access to specific IP ranges. The 'sign-in frequency' session control within Conditional Access ensures users re-authenticate (including MFA) at specified intervals, overriding persistent sessions for critical apps.

Why the other options are wrong

  • A. Persistent browser sessions would contradict the requirement for always using MFA, as they extend session validity without re-authentication.
  • B. Identity Protection detects risks, but doesn't enforce location or continuous MFA for specific apps. MFA registration policy is for initial setup, not continuous enforcement.
  • D. PIM is for just-in-time access for privileged roles, not for all users accessing a critical application. Authentication strength is for requiring specific MFA methods, but 'sign-in frequency' is needed for continuous re-authentication.

Conditional Access: Location & Sign-in Frequency

Azure AD Conditional Access policies allow granular control over resource access. The location condition restricts access based on IP ranges, while the sign-in frequency session control mandates re-authentication (including MFA) after a defined period, even if other sessions are active.

  • Location condition: Defines trusted IP ranges for access.
  • Sign-in frequency: Controls how often users must re-authenticate.
  • Crucial for high-security applications requiring continuous validation.
  • Overrides default session behavior like persistent browser sessions.

Memory trick: Location Lock, Frequent Login for Sensitive Secrets.

More Manage identity and access questions