Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You need to enforce multi-factor authentication (MFA) only when a set of Azure administrators access the Azure portal or perform management operations by using Azure PowerShell. Administrators should not be prompted for MFA when they sign in to other SaaS apps. You create an Azure AD group that contains the administrators. What should you configure to meet the requirement with the least administrative effort?
Enable Security Defaults for the Azure AD tenant.
Configure an Azure AD Identity Protection sign-in risk policy that requires MFA for medium and high risk sign-ins.
Create a Conditional Access policy that targets the administrator group and the Microsoft Azure Management cloud app and grants access only if MFA is satisfied.
Enable per-user Azure AD Multi-Factor Authentication for each administrator account.
A Conditional Access policy can be scoped to a specific group and a specific cloud app. Selecting the Microsoft Azure Management cloud app covers the Azure portal, Azure Resource Manager APIs, Azure PowerShell, and Azure CLI. Granting access only if MFA is satisfied forces the additional factor whenever the targeted administrators perform management tasks, while leaving their sign-ins to other enterprise applications unaffected. Enabling per-user MFA or Security Defaults prompts the users for MFA in many additional scenarios and requires more individual configuration. An Identity Protection sign-in risk policy is driven by risk levels, not by the specific Azure management endpoints required here.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Conditional Access in Azure AD?
Open an interactive chat with Bash
What is the Microsoft Azure Management cloud app?
Open an interactive chat with Bash
How does Azure AD Identity Protection evaluate sign-in risk levels?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .