AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company requires all users to use multi-factor authentication (MFA) when accessing cloud applications. However, they want to exempt users from MFA when they connect from the company's headquarters, which has a trusted IP range. They want to enforce this policy centrally. Which Microsoft Entra ID feature should they use?
⚠ Common exam trap
Many exam-takers confuse Identity Protection (which handles risk-based MFA prompts) with Conditional Access (which handles location-based MFA exemptions), leading them to select Identity Protection because it also deals with MFA, but it lacks the trusted IP range exclusion capability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Conditional Access
Microsoft Entra ID Conditional Access is the correct feature because it allows administrators to create policies that enforce MFA based on conditions such as user location, device state, and application sensitivity. By configuring a Conditional Access policy with a 'trusted location' condition (defined via named locations with specific IP ranges), the company can require MFA for all cloud app access except when users connect from the headquarters' trusted IP range. This provides centralized, granular control over authentication requirements without needing to modify individual user settings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra ID Conditional Access
Why this is correct
Microsoft Entra ID Conditional Access is the policy service that evaluates sign-in signals—such as user, device, and network location—to decide whether to block access or require additional authentication. To enforce MFA for all users except those connecting from trusted IP ranges, you would create a Conditional Access policy targeting All Users, set the location condition to 'Any location' with 'Exclude trusted IPs,' and configure the grant control 'Require multi-factor authentication.' This directly implements the stated requirement, and the same engine can also integrate risk signals from Identity Protection for layered policies.
- ✗
Microsoft Entra ID Identity Protection
Why it's wrong here
Microsoft Entra ID Identity Protection is primarily a risk-detection engine that uses signals like impossible travel, credential leaks, and anonymous IP addresses to assign a risk level to each sign-in. While it can feed those risk levels into Conditional Access for risk-based MFA challenges, it has no native mechanism to enforce MFA based purely on a location condition such as a trusted IP range. Therefore, Identity Protection alone cannot implement the company's 'MFA everywhere except trusted IPs' requirement; it relies on Conditional Access to perform the actual enforcement.
- ✗
Microsoft Entra ID Privileged Identity Management
Why it's wrong here
Microsoft Entra ID Privileged Identity Management (PIM) provides just-in-time and time-bound activation of privileged roles, with features like approval workflows and Multi-Factor Authentication required during role activation. However, PIM only governs the elevation into administrative roles; it does not apply to standard user sign-ins or general MFA enforcement. Thus, using PIM would not ensure that all users are prompted to pass MFA when accessing the tenant normally, so it falls short of the stated policy.
- ✗
Microsoft Entra ID Self-Service Password Reset
Why it's wrong here
Microsoft Entra ID Self-Service Password Reset allows users to reset a forgotten password by completing a verification process, typically using a pre-registered phone number, email, or security questions. This flow is designed for account recovery after a sign-in failure and does not control the original authentication event, nor does it provide a location-based policy to require MFA across the organization. Consequently, SSPR cannot satisfy the requirement to enforce MFA on all user sign-ins from non-trusted locations.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.