In this task, you will sign in to the Azure portal as aaduser2 and verify MFA is required. You will also delete the policy before continuing on to the next exercise.
Open an InPrivate Microsoft Edge window.
In the new browser window, navigate to the Azure portal and sign in with the aaduser2 user account.
When prompted, in the More information required dialog box, click Next.
Note: The browser seesion will be redirected to the Keep your account secure page.
On the Keep your account secure page, select the I want to set up a different method link, in the Which method would you like to use? drop-down list, select Phone, and select Confirm.
On the Keep your account secure page, select your country or region, type your mobile phone number in the Enter phone number area, ensure that the Text me a code option is selected, and click Next.
On the Keep your account secure page, type the code you received in the text message on your mobile phone, and click Next.
On the Keep your account secure page, ensure that the verification was successful and click Next.
On the Keep your account secure page, click Done.
When prompted, change your password. Make sure to record the new password.
Verify that you successfully signed in to the Azure portal.
Sign out as aaduser2 and close the InPrivate browser window.
Note: You have now verified that the newly created conditional access policy enforces MFA when aaduser2 signs into the Azure portal.
Back in the browser window displaying the Azure portal, navigate back to the AdatumLab500-04 Azure Active Directory tenant blade.
On the AdatumLab500-04 blade, in the Manage section, click Security.
On the Security | Getting started blade, in the Protect section, click Conditional Access.
On the Conditional Access | Policies blade, click the ellipsis next to AZ500Policy1, click Delete, and, when prompted to confirm, click Yes.
Note: Result: In this exercise you implement a conditional access policy to require MFA when a user signs into the Azure portal.
Result: You have configured and tested Azure AD conditional access.