Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionHard
A security administrator is investigating a series of suspicious sign-in attempts targeting several high-value accounts in Azure Active Directory (Azure AD). The attempts originate from unusual geographic locations and exhibit characteristics of credential stuffing attacks. The administrator needs to configure a policy that automatically blocks these suspicious sign-ins and alerts the security team. Which Azure AD feature provides the most effective solution for this scenario?
- AAzure AD Access Reviews to periodically check for compromised accounts.
- BAzure AD Conditional Access policy targeting suspicious locations.
- CAzure AD Identity Protection with 'Sign-in risk policy' configured to block access.
- DAzure AD Connect Health for monitoring synchronization errors.
Show answer & explanationAnswer & explanation
Correct answer: C. Azure AD Identity Protection with 'Sign-in risk policy' configured to block access.
Azure AD Identity Protection's 'Sign-in risk policy' is specifically designed to detect and respond to suspicious sign-in attempts, including those from unusual locations and credential stuffing. It can be configured to automatically block access and trigger alerts, directly addressing the scenario.
Why the other options are wrong
- A. Access Reviews are for periodic verification of access rights, not for real-time detection and blocking of suspicious sign-in attempts.
- B. Conditional Access can block based on 'unusual locations' but lacks the advanced machine learning and real-time risk detection capabilities for 'credential stuffing' that Identity Protection offers.
- D. Azure AD Connect Health monitors the health of synchronization components and federation services, not real-time sign-in risks.
Azure AD Identity Protection
Azure AD Identity Protection helps organizations detect, investigate, and remediate identity-based risks by identifying vulnerabilities and suspicious activities related to user identities.
- Detects user risk (compromised credentials) and sign-in risk (suspicious sign-in attempts).
- Can automatically remediate risks (e.g., force password reset, block access).
- Integrates with Conditional Access for enforcement.
- Generates reports and alerts for security teams.
Memory trick: IP: Identify Problems, Protect People.