Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A company uses Microsoft Entra ID (Microsoft Entra ID) Premium P2. They want to enforce that users accessing sensitive cloud applications from outside the corporate network must use multi-factor authentication (MFA). Which Microsoft Entra ID feature should they configure?

⚠ Common exam trap

Many candidates confuse Identity Protection's risk-based MFA triggers with Conditional Access's location-based MFA, assuming Identity Protection alone can enforce MFA for external access, but Identity Protection only suggests or triggers MFA via risk policies that require Conditional Access to actually enforce the block or MFA prompt.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access

Conditional Access is the correct feature because it allows administrators to define policies that enforce MFA based on specific conditions, such as network location (outside corporate network) and cloud app sensitivity. By configuring a Conditional Access policy targeting 'All cloud apps' or specific sensitive apps with the condition 'Locations: All trusted/untrusted networks', you can require MFA for external access. This directly meets the requirement without needing additional licenses or features beyond Entra ID Premium P2.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conditional Access

    Why this is correct

    Conditional Access is the correct answer because it is the policy engine that evaluates sign-in signals—such as user, group, location, device compliance, and session risk—and can require MFA for every user by creating a policy targeting 'All users' with the 'Require authentication strength' or 'Require multifactor authentication' grant control. It is tightly integrated with Entra ID Protection risk signals, allowing MFA to be enforced conditionally or universally, and supports excluding emergency access accounts to avoid lockout.

  • ✗

    Identity Protection

    Why it's wrong here

    Identity Protection is incorrect because it is a risk-detection service that identifies threats such as leaked credentials, impossible travel, and anomalous sign-in behavior, producing risk levels for users and sign-ins. It does not itself block access or prompt for MFA; rather, it publishes risk data that Conditional Access policies consume to trigger MFA or password reset. Without a Conditional Access policy linking the risk, Identity Protection can only alert or automate remediation after the fact.

  • ✗

    Privileged Identity Management

    Why it's wrong here

    Privileged Identity Management is incorrect because it is designed for just-in-time and time-bound activation of highly privileged Microsoft Entra ID roles, such as Global Administrator, requiring approval or multi-factor authentication for role activation. It does not impose MFA on normal end-user authentication to applications; its scope is limited to administrative role elevation, not a blanket MFA requirement for all users.

  • ✗

    Access Reviews

    Why it's wrong here

    Access Reviews is incorrect because it is an identity-governance feature for periodic attestation of existing access, where resource owners or reviewers confirm whether a user still needs group memberships or application roles. It can remove stale or inappropriate assignments after review, but it is not evaluated during interactive sign-in and cannot require MFA as a condition for access. Therefore, it addresses ongoing authorization hygiene, not authentication enforcement.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.