AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company uses Microsoft Entra ID (Microsoft Entra ID). They need to ensure that users who access sensitive cloud applications from untrusted networks (e.g., public Wi-Fi) are prompted for multi-factor authentication (MFA). Which Microsoft Entra ID feature should they configure?
⚠ Common exam trap
A common mix-up: candidates confuse Identity Protection's risk-based MFA with Conditional Access's location-based MFA, but Identity Protection alone cannot enforce MFA based solely on network location—it requires a Conditional Access policy to act on the risk signal.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access
Conditional Access policies in Microsoft Entra ID allow administrators to define conditions (e.g., network location, device state) under which access to cloud applications is granted. By configuring a policy that targets sensitive applications and requires MFA when the user's IP address is from an untrusted network (such as public Wi-Fi), the company can enforce MFA only when the risk condition is met, without affecting access from trusted corporate networks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access
Why this is correct
Conditional Access is the correct Microsoft Entra ID feature because it centrally evaluates authentication signals—such as user, device, and network location—and applies granular access controls. Administrators define named locations (e.g., office IP ranges) and create a policy that requires MFA when a sign-in originates from any other location. This policy-driven approach gives real-time, condition-based enforcement of MFA for untrusted networks.
- ✗
Identity Protection
Why it's wrong here
Microsoft Entra ID Protection detects identity risks—like impossible travel, leaked credentials, or anonymous IP addresses—and generates a sign-in risk or user risk score. It can trigger MFA or a password change as remediation when a risk threshold is exceeded, but it does not directly map a user's network location to an MFA requirement. Location is a static condition in Conditional Access, not a risk event that Identity Protection itself acts on.
- ✗
Privileged Identity Management (PIM)
Why it's wrong here
Privileged Identity Management (PIM) in Microsoft Entra ID is designed for just-in-time, time-bound activation of privileged administrator roles, including approval workflows and MFA on role activation. It does not evaluate the network location of a user's sign-in and cannot apply MFA based on whether the user is inside or outside a trusted network. PIM governs who can become an admin and when, not baseline sign-in conditions for all users.
- ✗
Microsoft Entra ID B2C
Why it's wrong here
Microsoft Entra ID B2C is an identity service intended for external customer identities (consumers, citizens, or app users) and runs in a separate B2C tenant with its own policy engine. Although B2C can require phone or email MFA through custom policies, it does not apply to an organization's internal employees governed by the primary Microsoft Entra ID tenant. Therefore, it cannot enforce location-based MFA for corporate internal users, making it an incorrect choice here.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.