Microsoft 365 FundamentalsDescribe security, compliance, privacy, and trust in Microsoft 365Medium
A Microsoft 365 administrator is configuring a new tenant and needs to ensure that users are always prompted for a second form of verification when signing in, regardless of their location or device, to strengthen account security. Which Azure AD identity management capability should the administrator implement to achieve this universal multi-factor authentication (MFA) enforcement?
- AAzure AD Identity Protection
- BAzure AD Conditional Access
- CAzure AD Connect
- DSecurity Defaults
Show answer & explanationAnswer & explanation
Correct answer: D. Security Defaults
Security Defaults in Azure AD provide a basic level of security for all organizations by enforcing common security best practices, including requiring all users to register for and use multi-factor authentication (MFA) for every sign-in by default, without complex configuration.
Why the other options are wrong
- A. Identity Protection detects and remediates risky sign-ins, but doesn't universally enforce MFA for all sign-ins regardless of risk.
- B. Conditional Access can enforce MFA, but it's a more granular, policy-driven approach that requires specific configuration. Security Defaults provide this universal enforcement with minimal setup.
- C. Azure AD Connect synchronizes identities and doesn't enforce MFA policies.
Azure AD Security Defaults
A set of pre-configured, Microsoft-managed identity security settings that provide a baseline level of protection for all Azure AD tenants, including universal multi-factor authentication (MFA) enforcement.
- Enforces MFA for all users and admins.
- Protects against common identity-related attacks.
- Simple to enable for immediate baseline security.
Memory trick: Security Defaults are the 'easy button' for universal MFA.