Isn't in wrong to block access in Sign in risk Conditional access policy and require MFA?

Amrit Kaur 0 Reputation points
2025-02-06T21:19:42.4+00:00

https://learn.microsoft.com/en-us/training/modules/manage-azure-active-directory-identity-protection/4-exercise-enable-sign-risk-policy
Isn't in wrong to block access in Sign in risk Conditional access policy and require MFA?

This question is related to the following Learning Module

Azure | Azure Training
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Divyesh Govaerdhanan 6,400 Reputation points
    2025-02-06T23:21:46.52+00:00

    Hello,

    Welcome to Microsoft Q&A,

    In a Sign-in Risk Conditional Access Policy, blocking access outright might not always be the best approach. Instead, requiring Multi-Factor Authentication (MFA) is often the recommended approach.

    Block Access might lead to a False positive (as it's AI-based signals), and it does not give the better user experience to verify their identity whereas MFA provides the user the ability to verify their identity.

    So, blocking access in a Sign-in Risk policy is not necessarily "wrong," but requiring MFA is a better and more flexible security measure in most cases.

    Please Upvote and accept the answer if it helps!


  2. Kiran P 8,225 Reputation points Microsoft External Staff Volunteer Moderator
    2025-02-25T07:43:07.0666667+00:00

    Hi Amrit Kaur,

    We reached out to the author of the module, and they confirmed that this is not an error, but rather a confusing user interface design. To open the Access menu, you need to click on the words "BLOCK ACCESS." From there, select "Grant Access," as the user has mentioned. I am adjusting the lab step to make it clearer, but the text is correct as written.

    Note: The module document will be updated soon.

    If you have found the answer provided to be helpful, please click on the "Accept answer/Upvote" button so that it is useful for other members in the Microsoft Q&A community.

    Thank you.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.