ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 344 - AZ-900 discussion

Report
Export

You need to ensure that when Azure Active Directory (Azure AD) users connect to Azure AD from the Internet by using an anonymous IP address, the users are prompted automatically to change their password. Which Azure service should you use?

A.
Azure AD Connect Health
Answers
A.
Azure AD Connect Health
B.
Azure AD Privileged Identity Management
Answers
B.
Azure AD Privileged Identity Management
C.
Azure Advanced Threat Protection (ATP)
Answers
C.
Azure Advanced Threat Protection (ATP)
D.
Azure AD Identity Protection
Answers
D.
Azure AD Identity Protection
Suggested answer: D

Explanation:

Azure AD Identity Protection includes two risk policies: sign-in risk policy and user risk policy. A sign-in risk represents the probability that a given authentication request isn't authorized by the identity owner. There are several types of risk detection. One of them is Anonymous IP Address. This risk detection type indicates sign-ins from an anonymous IP address (for example, Tor browser or anonymous VPN). These IP addresses are typically used by actors who want to hide their login telemetry (IP address, location, device, etc.) for potentially malicious intent. You can configure the sign-in risk policy to require that users change their password.

References: https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-sign-in-risk-policy https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-risks

asked 02/10/2024
Matthew McConnell
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first