Microsoft 365 FundamentalsDescribe security, compliance, privacy, and trust in Microsoft 365Medium
A Microsoft 365 administrator is implementing a new security policy where users attempting to log in from 'risky' IP addresses (known to be associated with cyber threats) must be challenged with multi-factor authentication, even if they are internal employees. This policy should also automatically block sign-ins from extremely high-risk locations. Which Azure AD feature is best suited for this granular, risk-based access control?
- AAzure AD Privileged Identity Management (PIM)
- BAzure AD Conditional Access
- CAzure AD Identity Protection
- DAzure AD Security Defaults
Show answer & explanationAnswer & explanation
Correct answer: B. Azure AD Conditional Access
Azure AD Conditional Access allows for granular, risk-based access control by defining 'if-then' statements. It can evaluate sign-in risk, device state, location, and other factors to enforce actions like requiring MFA, blocking access, or forcing password changes, making it ideal for this scenario.
Why the other options are wrong
- A. Azure AD PIM manages, controls, and monitors access to important resources within an organization, primarily for just-in-time access, not risk-based sign-in policy enforcement.
- C. Azure AD Identity Protection detects and remediates identity-based risks, but Conditional Access is the engine that applies policies based on these risk detections.
- D. Azure AD Security Defaults provide baseline security but lack the granular, risk-based control required by this scenario.
Azure AD Conditional Access
An Azure Active Directory feature that allows organizations to implement automated access control decisions based on conditions like user, location, device, and sign-in risk.
- Acts as an 'if-then' statement for access control.
- Integrates with Azure AD Identity Protection for risk signals.
- Can enforce MFA, block access, require compliant devices, etc.
- Requires an Azure AD Premium P1 license.
Memory trick: Conditions dictate who gets in and how.