Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudMedium

A security engineer is reviewing the secure score for an Azure subscription in Microsoft Defender for Cloud. They notice a recommendation to 'Enable multifactor authentication (MFA) on accounts with owner permissions on your subscription'. The engineer needs to implement a solution that automatically enforces this recommendation for all existing and new owner accounts across the subscription. Which of the following is the MOST appropriate action to take within Microsoft Defender for Cloud?

  1. ACreate an Azure Policy assignment that requires MFA for owner roles and assign it to the subscription.
  2. BImplement a custom Logic App to monitor owner role assignments and trigger MFA enforcement.
  3. CManually enable MFA for each owner account listed in the recommendation details.
  4. DDismiss the recommendation, as MFA enforcement is typically handled at the identity provider level.
Show answer & explanation

Correct answer: A. Create an Azure Policy assignment that requires MFA for owner roles and assign it to the subscription.

Azure Policy is the most effective and scalable way within Azure to automatically enforce configurations, such as requiring MFA for specific roles, across an entire subscription or management group. This ensures compliance for both existing and newly created resources/assignments.

Why the other options are wrong

  • B. While a Logic App could potentially monitor and trigger actions, Azure Policy is purpose-built for enforcing compliance and security configurations directly within Azure, making it a more direct and integrated solution for this specific requirement.
  • C. Manually enabling MFA is not an automated or scalable solution for enforcing the recommendation across all accounts, especially for new ones.
  • D. Dismissing the recommendation does not address the security gap; MFA enforcement is critical and can be enforced at the Azure resource level via policy.

Azure Policy for MFA Enforcement

Azure Policy can be used to enforce security requirements, such as requiring Multi-Factor Authentication (MFA) for specific administrative roles, ensuring compliance and enhancing security posture across Azure resources.

  • Automates compliance checks and enforcement.
  • Can target subscriptions, management groups, or resource groups.
  • Ensures consistent security configurations.
  • Helps improve secure score by addressing recommendations.

Memory trick: Policy's plan: Protect owners, Prevent breaches, Perfect posture.

More Mitigate threats using Microsoft Defender for Cloud questions