Microsoft
AZ-104 · Question #358
You are the global administrator for an Azure Directory (Azure AD) tenant named adatum.com. You need to enable two-step verification for Azure users. What should you do?
The correct answer is A. Create a single sign-in risk policy in Azure AD Identity Protection.. With Azure Active Directory Identity Protection, you can: require users to register for multi-factor authentication handle risky sign-ins and compromised users https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/flows
Submitted by helene.fr· Mar 4, 2026Manage Azure identities and governance
Question
You are the global administrator for an Azure Directory (Azure AD) tenant named adatum.com. You need to enable two-step verification for Azure users. What should you do?
Options
- ACreate a single sign-in risk policy in Azure AD Identity Protection.
- BEnable Azure AD Privileged Identity Management.
- CCreate and configure the Identity Hub.
- DConfigure a security policy in Azure Security Center.
How the community answered
(21 responses)- A81% (17)
- B5% (1)
- C10% (2)
- D5% (1)
Explanation
With Azure Active Directory Identity Protection, you can: require users to register for multi-factor authentication handle risky sign-ins and compromised users https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/flows
Community Discussion
No community discussion yet for this question.