Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

A company is implementing a new security policy that requires all users to register for multi-factor authentication (MFA) within 14 days of their account creation or first sign-in. If they fail to register within this period, they should be prompted to register until they complete the process. Which Azure AD Identity Protection policy should be configured to enforce this requirement efficiently?

  1. AUser risk policy
  2. BSign-in risk policy
  3. CMFA registration policy
  4. DConditional Access policy
Show answer & explanation

Correct answer: C. MFA registration policy

The MFA registration policy specifically targets users who have not yet registered for multi-factor authentication and can be configured to require registration after a set number of days. This directly addresses the company's requirement.

Why the other options are wrong

  • A. User risk policies detect risky user behavior and prompt for password changes or block access, not MFA registration.
  • B. Sign-in risk policies detect suspicious sign-in attempts and can block or require MFA, but not specifically enforce initial MFA registration.
  • D. While Conditional Access can enforce MFA, it does not have a built-in mechanism to track and enforce initial MFA registration after a specific grace period like the Identity Protection MFA registration policy.

MFA Registration Policy

An Azure AD Identity Protection policy designed to ensure users register for multi-factor authentication, often with a grace period.

  • Enforces MFA registration for non-registered users.
  • Can set a grace period (e.g., days after first sign-in).
  • Part of Azure AD Identity Protection.

Memory trick: MFA Register: The Policy that MAKES you register.

More Implement an identity management solution questions