Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

You are a solutions architect for a large healthcare organization that uses Microsoft 365 and Azure. The organization has a Microsoft Entra ID tenant with 15,000 users. The security team requires that all users use multi-factor authentication (MFA) when accessing cloud applications. Currently, only 60% of users have registered for MFA. The organization wants to enforce MFA registration for all users within 30 days. The solution must minimize user disruption and allow users to register their MFA methods during their normal work hours. The organization uses Microsoft Intune for mobile device management and has a conditional access policy that requires MFA for all cloud apps. You need to design a solution to enforce MFA registration. What should you do?

⚠ Common exam trap

Watch out — candidates often confuse enforcement of MFA at sign-in (Conditional Access) with the proactive registration workflow (MFA registration campaign), leading candidates to choose Option A which would cause immediate disruption instead of a phased, user-friendly registration process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure a Microsoft Entra ID MFA registration campaign to target all users and require registration within 14 days.

A Microsoft Entra ID MFA registration campaign is specifically designed to nudge users to register for MFA with a configurable deadline (up to 14 days) without immediately blocking access. This minimizes disruption by allowing users to register during normal work hours, and it integrates with existing Conditional Access policies that require MFA for cloud apps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Modify the existing conditional access policy to require MFA for all cloud apps and block access if MFA is not registered.

    Why it's wrong here

    Modifying the conditional access policy to require MFA for all cloud apps does not itself trigger MFA registration; it only enforces MFA at sign-in after a user has already registered. Adding a 'block access if MFA is not registered' condition would lock out unregistered users entirely, causing a disruptive denial of service rather than guiding them through the registration process. The correct approach is to use a registration campaign, which nudges users to register before strict MFA enforcement is applied.

  • Deploy an Intune compliance policy that requires MFA enrollment on mobile devices.

    Why it's wrong here

    Intune compliance policies evaluate device health and configuration settings—such as OS version, encryption, or jailbreak status—and do not have a setting to enforce user MFA registration. While a compliance policy can require device-level controls like a PIN or biometric, MFA registration is a user-level authentication method property stored in Microsoft Entra ID, not a device compliance attribute. Deploying such a policy would leave user MFA registration untouched and could fail device compliance checks for unrelated reasons.

  • Configure a Microsoft Entra ID MFA registration campaign to target all users and require registration within 14 days.

    Why this is correct

    The Microsoft Entra ID MFA registration campaign is the purpose-built feature to drive adoption by targeting all users, setting a required registration deadline (e.g., 14 days), and gradually reminding them to register without immediately blocking access. Users can snooze or delay the prompt for a limited time, which avoids disruption while still moving the entire tenant toward MFA readiness. This campaign works alongside conditional access policies and is the recommended first step before enforcing MFA for all cloud apps.

  • Use Microsoft Entra ID password reset policy to force users to register MFA during password reset.

    Why it's wrong here

    A Microsoft Entra ID password reset policy governs self-service password reset (SSPR) and may require users to verify identity using existing authentication methods, but it does not force or track MFA registration for later sign-in. Users could reset their password using an email or security question without ever registering a phone or authenticator app, leaving them unregistered for MFA. SSPR registration and MFA registration are separate lifecycle events, so this approach would not reliably fulfill a tenant-wide MFA enrollment requirement.

About these practice questions

This AZ-305 question is part of Courseiva's 212-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.