AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company uses Microsoft Entra ID. They want to require users to use multi-factor authentication when accessing the Azure portal from any device. They do not want to require MFA for other applications. Which Microsoft Entra ID feature should they configure?
⚠ Common exam trap
Test-takers frequently confuse Security defaults (which is a blanket MFA enforcement for all apps) with the ability to scope MFA to a single application, leading them to choose Security defaults instead of the more precise Conditional Access policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policy targeting Azure Portal
Conditional Access policies allow granular control over authentication requirements based on conditions such as application, user, location, or device state. By creating a policy that targets the 'Microsoft Azure Management' cloud app and requires multi-factor authentication, you can enforce MFA specifically for the Azure portal without affecting other applications. This provides the precise control requested, unlike broader or legacy methods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access policy targeting Azure Portal
Why this is correct
A Conditional Access policy that targets the Azure Portal is the correct solution because you can select the 'Microsoft Azure Management' cloud app (the enterprise application that represents the Azure portal and API management) and require MFA as a grant control. This policy is evaluated by the Conditional Access engine at sign-in and applies only to the selected app, leaving MFA behavior for other applications unaffected. You can further scope it by users, groups, locations, or device state to meet the company's exact requirement.
- ✗
Per-user MFA (legacy)
Why it's wrong here
Configuring per-user MFA from the Entra ID user properties sets a persistent state (Disabled, Enabled, or Enforced) on the user account that governs all authentication flows. When enabled or enforced, the user is challenged for MFA on every interactive sign-in across every cloud application integrated with Entra ID, including Office 365, Exchange Online, and all other SaaS apps. It cannot target just the Azure Portal, so it is an over-broad, legacy approach that fails the requirement to limit MFA to a single app.
- ✗
Security defaults
Why it's wrong here
Security defaults are pre-configured tenant-wide protections that apply MFA to all users for all cloud applications, block legacy authentication, and require AAD admins to use MFA. This setting is global and cannot be filtered by application, so enabling it would require MFA not only for the Azure Portal but also for every other app the company uses. The requirement asks for a specific app scope, and security defaults lack that granularity, making it incorrect.
- ✗
Identity Protection
Why it's wrong here
Identity Protection is a risk-detection and remediation service that surfaces sign-in risks, user risks, or vulnerabilities and can trigger policies, such as requiring MFA based on a risk level like high or medium. Those risk-based MFA prompts are conditional on detected anomalies, not a standing, unconditional requirement for a specific application. It cannot force MFA for every sign-in to the Azure Portal on its own; that granular control is a Conditional Access capability. Thus, Identity Protection is not a direct answer to the requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.