SC-300 · Question #65
You have an Azure Active Directory (Azure AD) tenant named contoso.com that has Azure AD Identity Protection enabled. You need to implement a sign-in risk remediation policy without blocking user…
The correct answer is D. Implement multi-factor authentication (MFA) for all users. To implement a sign-in risk remediation policy. When a sign in risk policy triggers: Azure AD MFA can be triggered, allowing to user to prove it's them by using one of their registered authentication methods, resetting the sign in risk…
Question
You have an Azure Active Directory (Azure AD) tenant named contoso.com that has Azure AD Identity Protection enabled. You need to implement a sign-in risk remediation policy without blocking user access. What should you do first?
Options
- AConfigure access reviews in Azure AD.
- BEnforce Azure AD Password Protection.
- CConfigure self-service password reset (SSPR) for all users.
- DImplement multi-factor authentication (MFA) for all users.
How the community answered
(55 responses)- A7% (4)
- B11% (6)
- C4% (2)
- D78% (43)
Explanation
To implement a sign-in risk remediation policy. When a sign in risk policy triggers: Azure AD MFA can be triggered, allowing to user to prove it's them by using one of their registered authentication methods, resetting the sign in risk. https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity- protection-configure-risk-policies
Topics
Community Discussion
No community discussion yet for this question.