A security engineer is reviewing the secure score for an Azure subscription in Microsoft Defender for Cloud. They notice a recommendation to "Enable MFA on subscriptions" with a high impact on the secure score. The organization has a strict policy to enforce Multi-Factor Authentication (MFA) for all administrative accounts accessing Azure resources. The engineer wants to implement an Azure Policy that not only identifies non-compliant accounts but also automatically enforces MFA for them. Which Azure Policy capability should be used to achieve this automatic enforcement?
- ADeny
- BAuditIf NotExists
- CDeployIf NotExists
- DModify
Show answer & explanationAnswer & explanation
Correct answer: D. Modify
The 'Modify' effect in Azure Policy is used to add, update, or delete properties or tags on a subscription or resource during creation or update. While MFA enforcement is typically done at the Azure AD level, if the question implies a policy that *modifies* a setting on the subscription or resource to *enable* MFA enforcement (e.g., setting a property to require MFA for specific operations, or modifying a built-in policy assignment that enforces MFA), 'Modify' would be the most suitable effect for *automatic enforcement* compared to just auditing or deploying a separate resource. For direct MFA enforcement on user accounts, Azure AD Conditional Access is primary, but Azure Policy 'Modify' can enforce related settings or link to built-in policies that trigger MFA enforcement.
Why the other options are wrong
- A. Deny would prevent actions that don't meet MFA requirements, but doesn't automatically enforce MFA.
- B. AuditIf NotExists only reports non-compliance without taking any enforcement action.
- C. DeployIf NotExists is for deploying resources or extensions if they don't exist, not typically for modifying existing user/account settings like MFA directly.
Azure Policy 'Modify' Effect for Enforcement
The 'Modify' effect in Azure Policy is used to add, update, or delete properties or tags on a subscription or resource. It can be used to automatically enforce security settings by modifying resource properties to meet compliance standards, such as enabling MFA-related settings or parameters within a policy definition.
- Automatically updates properties of existing resources/subscriptions.
- Requires a managed identity for remediation.
- Can enforce configurations like MFA settings or tagging standards.
Memory trick: To change a setting, make it true, the Modify effect will see it through.