Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A company uses Microsoft Entra ID for identity management. They want to ensure that users accessing sensitive data from unmanaged devices are prompted for multifactor authentication (MFA) and must accept a terms-of-use. Which policy should be configured?

⚠ Common exam trap

Many candidates confuse a standalone Terms-of-use policy (Option A) with the ability to enforce it conditionally, not realizing that Conditional Access is required to tie the terms-of-use acceptance to a specific condition like unmanaged devices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access policy

Conditional Access policies in Microsoft Entra ID allow granular control over access based on conditions such as device state (managed vs. unmanaged). By configuring a policy that targets unmanaged devices, you can enforce MFA and require acceptance of a terms-of-use before granting access to sensitive data. This directly meets the requirement without needing separate policies for MFA and terms-of-use.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Terms-of-use policy

    Why it's wrong here

    Terms-of-use in Microsoft Entra ID is a document-based consent artifact that users must accept before access, but it is not an evaluation engine. It cannot inspect whether a device is managed, hybrid joined, or compliant, nor can it require a second authentication factor like MFA. To enforce MFA or restrict unmanaged devices, the terms-of-use must be referenced as a grant control within a Conditional Access policy, not deployed alone.

  • ✓

    Conditional Access policy

    Why this is correct

    Conditional Access is the correct policy mechanism because it combines signals—such as device platform, join state, compliance status, and location—into conditions that apply at sign-in. You can target unmanaged devices by using a device filter for 'not hybrid Microsoft Entra ID joined' or 'not compliant', and then require both MFA and an accepted terms-of-use as grant controls. This gives you a single policy that enforces authentication strength and consent only when the device is unmanaged.

  • ✗

    Identity Protection policy

    Why it's wrong here

    Identity Protection focuses on automated response to risk signals like leaked credentials, atypical travel, or impossible travel, and its policies are limited to blocking or requiring MFA when risk thresholds are met. It does not expose device management or device ownership as a condition, so you cannot use it to target 'unmanaged devices' directly. Even if a user is low risk, the policy cannot independently require a terms-of-use acceptance based solely on the device being unmanaged.

  • ✗

    Privileged Identity Management (PIM) policy

    Why it's wrong here

    Privileged Identity Management (PIM) governs administrative roles by providing time-bound activation, approval workflows, and audit history for privileged assignments. It operates at the entitlement layer—deciding whether a user can activate the Global Administrator role—not at the authentication or device access layer. PIM has no knowledge of whether the user's endpoint is managed or unmanaged, and it cannot enforce MFA or terms-of-use against a nonprivileged application request.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.