Courseiva

AZ-104 Manage Azure Identities and Governance Practice Question

You are the global administrator for an Microsoft Entra ID tenant that is synchronized with an on-premises Active Directory using Microsoft Entra Connect. You need to implement a solution that requires users to authenticate with a second factor only when they access specific cloud applications, while users accessing other applications are not prompted. You also need to block authentication attempts from countries where the company does not operate. Which two features should you configure? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse Microsoft Entra ID MFA settings with Conditional Access, or assuming Identity Protection can block specific countries, when it is risk-based rather than location-deterministic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra Conditional Access policies

Conditional Access policies are the primary tool to enforce MFA for specific applications and to block access based on location. Named locations define the countries to block and are referenced in those policies. Together, they provide the granular, per-app and per-country control required. Identity Protection, MFA settings, and entitlement management do not offer the same deterministic targeting for applications and static geographic locations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra ID entitlement management access packages

    Why it's wrong here

    Entitlement management is used for managing access to groups, applications, and SharePoint sites through access packages with approval workflows and reviews. It does not enforce authentication methods like MFA or block sign-ins based on location. It is focused on access lifecycle management, not on conditional authentication or geographic restrictions, so it does not meet the requirements.

  • ✓

    Microsoft Entra Conditional Access policies

    Why this is correct

    Conditional Access policies allow you to enforce multifactor authentication for specific cloud applications and to block sign-ins from certain locations based on IP geolocation. By creating policies that target specific apps and include location conditions, you can meet both requirements. Conditional Access is the correct feature for granular, per-app, and per-location access control in Microsoft Entra ID.

  • ✗

    Microsoft Entra ID Multi-Factor Authentication (MFA) settings

    Why it's wrong here

    Microsoft Entra ID MFA settings allow you to require MFA for all users or specific users, but they do not provide per-application granularity or location-based blocking. They are a legacy method that applies MFA globally or per user. For the required granular control, Conditional Access is the appropriate feature. MFA settings alone cannot target specific cloud applications or block by country.

  • ✗

    Microsoft Entra ID Protection risk policies

    Why it's wrong here

    Identity Protection risk policies evaluate sign-in and user risk to automatically respond to detected threats, such as leaked credentials or atypical travel. While they can enforce MFA or block access, they are based on risk detection, not on specific application targeting or static country blocking. They do not provide the deterministic per-app and per-country control required.

  • ✓

    Microsoft Entra ID named locations

    Why this is correct

    Named locations let you define trusted IP ranges or countries. You can then use these named locations in Conditional Access policies to block or allow access from specific countries. Configuring a named location for the countries where the company does not operate and referencing it in a Conditional Access policy fulfills the requirement to block authentication attempts from those countries.

About these practice questions

Courseiva writes every AZ-104 question from scratch — 1,053 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.