Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Exhibit

Refer to the exhibit.
```json
{
  "policy": {
    "tenantId": "contoso.onmicrosoft.com",
    "conditions": {
      "applications": ["All"]
    },
    "grantControls": {
      "builtInControls": ["mfa", "approvedApplication"],
      "operator": "AND"
    },
    "sessionControls": {
      "applicationEnforcedRestrictions": null,
      "cloudAppSecurity": {
        "cloudAppSecurityType": "monitorOnly"
      },
      "signInFrequency": {
        "value": 1,
        "type": "hours"
      },
      "persistentBrowser": {
        "isEnabled": false
      }
    }
  }
}
```

You are reviewing a Conditional Access policy for a Microsoft Entra ID tenant. The exhibit shows the policy configuration. Users report that they are prompted for MFA every hour even when using approved Microsoft applications. The security team wants to reduce MFA prompts but maintain security. What should you modify?

⚠ Common exam trap

Candidates often confuse session controls like 'persistentBrowser' with sign-in frequency, assuming that keeping the browser session alive will also reduce MFA prompts, but sign-in frequency is a separate, explicit time-based re-authentication control that overrides session persistence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Increase the signInFrequency value to 24 hours

The sign-in frequency control in Conditional Access determines how often a user must re-authenticate. Increasing the value from 1 hour to 24 hours directly reduces the frequency of MFA prompts while still requiring re-authentication daily, balancing security and user experience. This change applies to approved Microsoft applications as configured in the policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable 'persistentBrowser' session control

    Why it's wrong here

    Enabling the persistentBrowser session control only extends the lifetime of the browser authentication cookie, so users won't be prompted to re-authenticate when revisiting the same browser. However, this control applies exclusively to browser-based access and does not affect the sign-in frequency for non-interactive or non-browser clients. The core problem is that MFA prompts occur too often across all applications, which is governed by the signInFrequency setting, not by browser persistence.

  • ✗

    Change cloudAppSecurityType to 'blockDownloads'

    Why it's wrong here

    Changing cloudAppSecurityType to 'blockDownloads' is a session-level restriction that blocks file downloads from supported Microsoft 365 apps to prevent data exfiltration. This control has no bearing on authentication token lifetime or the frequency of MFA prompts; it only reacts to user actions after the user is already signed in. Consequently, it would degrade user productivity without reducing the number of authentication challenges, so it is the wrong solution for the stated issue.

  • ✗

    Remove the 'approvedApplication' grant control

    Why it's wrong here

    Removing the 'approvedApplication' grant control would expand access to unapproved apps, eroding the security boundary that only vetted clients are allowed to use corporate resources. This control is orthogonal to the sign-in frequency mechanism; it does not alter how often users must provide MFA credentials. Thus, this action would weaken security and still leave the MFA prompt frequency unchanged, making it both counterproductive and ineffective.

  • ✓

    Increase the signInFrequency value to 24 hours

    Why this is correct

    Increasing the signInFrequency value to 24 hours directly reduces how often a user must re-authenticate, because this setting dictates the maximum time allowed between credential entries for all assigned apps. By setting it to a full day, users will only be challenged once within any 24-hour window, alleviating the frequent MFA prompts while still requiring periodic verification to maintain a reasonable security baseline. This is the correct adjustment because it targets the exact parameter that controls prompt cadence without weakening other access controls.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.