Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudHard

A security engineer is reviewing the secure score for an Azure subscription in Microsoft Defender for Cloud. They notice a recommendation to "Enable MFA on subscriptions" with a high impact on the secure score. The organization has a strict policy to enforce Multi-Factor Authentication (MFA) for all administrative accounts accessing Azure resources. The engineer wants to implement an Azure Policy that not only identifies non-compliant accounts but also automatically enforces MFA for them. Which Azure Policy capability should be used to achieve this automatic enforcement?

  1. ADeny
  2. BAuditIf NotExists
  3. CDeployIf NotExists
  4. DModify
Show answer & explanation

Correct answer: D. Modify

The 'Modify' effect in Azure Policy is used to add, update, or delete properties or tags on a subscription or resource during creation or update. While MFA enforcement is typically done at the Azure AD level, if the question implies a policy that *modifies* a setting on the subscription or resource to *enable* MFA enforcement (e.g., setting a property to require MFA for specific operations, or modifying a built-in policy assignment that enforces MFA), 'Modify' would be the most suitable effect for *automatic enforcement* compared to just auditing or deploying a separate resource. For direct MFA enforcement on user accounts, Azure AD Conditional Access is primary, but Azure Policy 'Modify' can enforce related settings or link to built-in policies that trigger MFA enforcement.

Why the other options are wrong

  • A. Deny would prevent actions that don't meet MFA requirements, but doesn't automatically enforce MFA.
  • B. AuditIf NotExists only reports non-compliance without taking any enforcement action.
  • C. DeployIf NotExists is for deploying resources or extensions if they don't exist, not typically for modifying existing user/account settings like MFA directly.

Azure Policy 'Modify' Effect for Enforcement

The 'Modify' effect in Azure Policy is used to add, update, or delete properties or tags on a subscription or resource. It can be used to automatically enforce security settings by modifying resource properties to meet compliance standards, such as enabling MFA-related settings or parameters within a policy definition.

  • Automatically updates properties of existing resources/subscriptions.
  • Requires a managed identity for remediation.
  • Can enforce configurations like MFA settings or tagging standards.

Memory trick: To change a setting, make it true, the Modify effect will see it through.

More Mitigate threats using Microsoft Defender for Cloud questions