Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your organization uses Microsoft Entra ID and requires that all external users invited via B2B collaboration must authenticate using multi-factor authentication (MFA). You need to enforce this for all guest users. What should you configure?

⚠ Common exam trap

A common mix-up: candidates confuse MFA registration (a prerequisite) with MFA enforcement (a runtime control), leading candidates to select Option C, which only ensures users have registered for MFA but does not require them to actually use it during sign-in.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra Conditional Access policy

Conditional Access policies in Microsoft Entra ID allow you to enforce MFA for guest users by targeting the 'Guest or external users' identity type and requiring MFA as a grant control. This provides granular control over authentication requirements for B2B collaboration users, unlike the other options which either lack enforcement capability or apply to different scenarios.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra B2B collaboration settings

    Why it's wrong here

    Microsoft Entra B2B collaboration settings govern the invitation, redemption, domain allow/block lists, and guest invite permissions, but they do not evaluate authentication requirements at sign-in time. These settings control who can be invited and how guests access resources, not whether a guest is prompted for MFA. To enforce MFA for guests, you must use Conditional Access, which is the actual authentication control layer.

  • ✗

    Microsoft Entra Identity Protection user risk policy

    Why it's wrong here

    The Microsoft Entra Identity Protection user risk policy operates reactively by detecting risky behaviors like leaked credentials or impossible travel, and then applying remediation actions such as requiring MFA or password change when a risk level is met. It does not proactively require MFA for all guest users on every sign-in attempt, nor does it enforce MFA as a blanket policy. Since it only triggers when risk is detected, it cannot guarantee that every guest authentication is challenged with MFA.

  • ✗

    Microsoft Entra ID MFA registration policy

    Why it's wrong here

    The Microsoft Entra ID MFA registration policy ensures that users have enrolled in MFA methods (e.g., authenticator app, phone number) but it does not enforce MFA during the sign-in process. Registration is a prerequisite that enables the user to respond to an MFA prompt, yet the policy itself never blocks or challenges a sign-in. The actual enforcement—such as requiring MFA for every guest—must be applied via a Conditional Access grant control.

  • ✓

    Microsoft Entra Conditional Access policy

    Why this is correct

    A Microsoft Entra Conditional Access policy is the correct mechanism because it can target guest users—or all external identities—and apply the "Require MFA" grant control directly at each authentication attempt. You can further scope the policy to specific cloud apps, conditions, or locations, giving fine-grained enforcement. This is the standard identity-driven control for ensuring guests must complete MFA before accessing resources, making it the only option here that actually forces MFA at sign-in.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.