Azure AD Identity Protection Flashcards
1
Q
Azure AD Identity Protection policies
A
- User-risk policy: can be used to define what happens when identity protection determines what an account may be compromised. Allows you to require password reset for allow access.
- Sign-in risk policy: allows you to enforce organizational requirements based on the risk score that indentity protection calculates for a particular sign-in. Allows you to require MFA with all access.
- MFA registration policy: allows you to force users to register for MFA
-This is the simplier version of AD Conditional Access
-You can set up alerts and reports of those policies
-P2 feature!
-Works for users and service principals
2
Q
Azure AD Identity Protection permissions needed to access
A
-Security reader
-Security operator
-security administrator
-Global reader
-Global Administrator