AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company uses Microsoft Entra ID. They want to enforce that all users must use multi-factor authentication (MFA) when accessing sensitive applications from outside the corporate network, but allow access without MFA when coming from the corporate office IP range. Which Microsoft Entra ID feature should they use to create this policy?
⚠ Common exam trap
Many candidates confuse Identity Protection's risk-based policies with Conditional Access's location-based MFA enforcement, assuming that risk policies can also enforce MFA based on network location, but Identity Protection only triggers MFA based on risk level, not static IP ranges.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policy
Conditional Access policies in Microsoft Entra ID allow administrators to define access controls based on conditions such as user location, device state, and application sensitivity. By creating a policy that requires MFA for all users accessing sensitive applications from outside the corporate network, and excluding the trusted corporate office IP range from the MFA requirement, the company can enforce the desired behavior. This is the correct feature because it directly supports location-based access controls and granular policy conditions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access policy
Why this is correct
Conditional Access is the Entra ID engine for evaluating access signals, including IP geolocation via named locations, and then applying grant controls such as requiring MFA. A policy can be scoped to users and apps, and for the 'location' condition, an untrusted or unfamiliar IP address triggers the MFA grant control, while trusted corporate IPs may skip it. This directly enforces MFA only when needed, matching the requirement.
- ✗
Identity Protection
Why it's wrong here
Identity Protection is a risk-detection service that identifies potentially compromised accounts by analyzing anomalies like impossible travel and leaked credentials. It produces risk signals (user risk and sign-in risk) that can be consumed by Conditional Access policies, but it does not itself contain a location condition or a direct MFA enforcement action. Therefore, while it can be integrated, it cannot alone enforce MFA based on IP location.
- ✗
Privileged Identity Management (PIM)
Why it's wrong here
Privileged Identity Management (PIM) is designed for managing and activating highly privileged Entra ID roles, providing just-in-time access with approval workflows and time-bound activation. It can require MFA when an admin activates a role, but it does not govern ordinary end-user sign-in or apply MFA based on the user's IP location. Thus it is not the right tool for location-based MFA enforcement across the company.
- ✗
Microsoft Entra ID roles
Why it's wrong here
Microsoft Entra ID roles, such as 'Global Administrator' or 'User Administrator,' define administrative permissions and scope of management through role-based access control (RBAC). These roles control what an admin can see or do in the tenant, not how users authenticate or what MFA requirements are applied during sign-in. Access policies for end-user MFA are configured in Conditional Access, not by assigning an Entra ID role.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.