Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionHard

A security administrator is investigating a series of suspicious sign-in attempts targeting several high-value accounts in Azure Active Directory (Azure AD). The attempts originate from unusual geographic locations and exhibit characteristics of credential stuffing attacks. The administrator needs to configure a policy that automatically blocks these suspicious sign-ins and alerts the security team. Which Azure AD feature provides the most effective solution for this scenario?

  1. AAzure AD Access Reviews to periodically check for compromised accounts.
  2. BAzure AD Conditional Access policy targeting suspicious locations.
  3. CAzure AD Identity Protection with 'Sign-in risk policy' configured to block access.
  4. DAzure AD Connect Health for monitoring synchronization errors.
Show answer & explanation

Correct answer: C. Azure AD Identity Protection with 'Sign-in risk policy' configured to block access.

Azure AD Identity Protection's 'Sign-in risk policy' is specifically designed to detect and respond to suspicious sign-in attempts, including those from unusual locations and credential stuffing. It can be configured to automatically block access and trigger alerts, directly addressing the scenario.

Why the other options are wrong

  • A. Access Reviews are for periodic verification of access rights, not for real-time detection and blocking of suspicious sign-in attempts.
  • B. Conditional Access can block based on 'unusual locations' but lacks the advanced machine learning and real-time risk detection capabilities for 'credential stuffing' that Identity Protection offers.
  • D. Azure AD Connect Health monitors the health of synchronization components and federation services, not real-time sign-in risks.

Azure AD Identity Protection

Azure AD Identity Protection helps organizations detect, investigate, and remediate identity-based risks by identifying vulnerabilities and suspicious activities related to user identities.

  • Detects user risk (compromised credentials) and sign-in risk (suspicious sign-in attempts).
  • Can automatically remediate risks (e.g., force password reset, block access).
  • Integrates with Conditional Access for enforcement.
  • Generates reports and alerts for security teams.

Memory trick: IP: Identify Problems, Protect People.

More Implement an authentication and access management solution questions