You have a new Azure subscription and are building an internal site that uses Azure AD for authentication. You must implement multifactor authentication (MFA) for the site. Which two actions are required? (Each correct answer is part of the solution.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new conditional access policy in Azure AD., Upgrade to Azure AD Premium..
Why this is the answer
Implementing MFA for an internal site using Azure AD requires two key actions. First, you must upgrade to Azure AD Premium. Conditional Access, which is necessary for enforcing MFA, is a feature available only with Azure AD Premium P1 or P2 licenses. Second, you need to create a new conditional access policy in Azure AD. This policy allows you to define the conditions under which MFA will be required, such as for specific users, groups, applications, or locations. Configuring the website to use Azure AD B2C is incorrect because B2C is for customer-facing applications, not internal sites using an existing Azure AD tenant. Enabling Application Proxy is for providing secure remote access to on-premises web applications, which is not directly related to enforcing MFA for an Azure-hosted internal site. While baseline policies exist, creating a new, custom conditional access policy offers the flexibility needed to precisely control MFA enforcement for your specific internal site requirements.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed