AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Exhibit
Refer to the exhibit.
```json
{
"properties": {
"displayName": "Require MFA for admins",
"conditions": {
"users": {
"includeUsers": ["All"]
},
"applications": {
"includeApplications": ["All"]
},
"clientAppTypes": ["browser", "mobileAppsAndDesktopClients"]
},
"grantControls": {
"builtInControls": ["mfa"]
}
}
}
```Refer to the exhibit. You create this Conditional Access policy in Microsoft Entra ID. What is the result?
⚠ Common exam trap
Watch out — candidates often assume a policy targeting 'All users' only applies to internal users or that 'All cloud apps' excludes certain Microsoft services, but in reality both scopes are comprehensive and include external users and every registered application.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
All users are prompted for MFA when accessing any application from a browser or mobile app.
The exhibit shows a Conditional Access policy that applies to 'All users' and targets 'All cloud apps' with the grant control set to 'Require multi-factor authentication'. This configuration forces every user, including administrators and external users, to complete MFA when accessing any cloud application from any platform (browser or mobile app). Option B correctly states this universal MFA requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Only administrators are prompted for MFA.
Why it's wrong here
The Conditional Access policy assigns to 'All users', not to a directory role, so administrator status does not narrow the policy's scope. The grant control requiring MFA applies universally to every included user object in the tenant, including members and guests, not just those with privileged roles. Therefore, the statement that only administrators are prompted incorrectly suggests a role-based filter that this policy does not contain.
- ✓
All users are prompted for MFA when accessing any application from a browser or mobile app.
Why this is correct
Because the policy includes 'All users', 'All cloud apps', and the grant control 'Require multi-factor authentication', every user in the tenant must perform MFA when accessing any application. The client app type configuration restricts enforcement to browser-based sessions and mobile apps using modern authentication, such as logging in through a browser or an app like Microsoft Authenticator. This produces a consistent MFA prompt for all internal users and any guest accounts present in the directory, across all registered applications.
- ✗
External users are prompted for MFA.
Why it's wrong here
The 'All users' assignment does target guest and external identities that have been added to the directory, so B2B collaboration users will indeed be prompted. However, the policy's scope is not exclusively external — it also covers every internal employee, which makes the description misleading because it singles out a subset. In Conditional Access, external users are prompted as part of the broader 'All users' group, not because the policy is specifically designed for them.
- ✗
Access is blocked for all users.
Why it's wrong here
The grant control selected is 'Require multi-factor authentication', not 'Block access', so a user who supplies the correct second factor is granted access to the application. Block access would be a separate grant control that immediately terminates the sign-in without allowing an MFA challenge. Thus the policy forces authentication beyond a password rather than denying entry, and any statement that all access is blocked misreads the effect of the grant control.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.