AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Your organization uses Microsoft Entra ID and requires that all external users invited via B2B collaboration must authenticate using multi-factor authentication (MFA). You need to enforce this for all guest users. What should you configure?
⚠ Common exam trap
A common mix-up: candidates confuse MFA registration (a prerequisite) with MFA enforcement (a runtime control), leading candidates to select Option C, which only ensures users have registered for MFA but does not require them to actually use it during sign-in.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Conditional Access policy
Conditional Access policies in Microsoft Entra ID allow you to enforce MFA for guest users by targeting the 'Guest or external users' identity type and requiring MFA as a grant control. This provides granular control over authentication requirements for B2B collaboration users, unlike the other options which either lack enforcement capability or apply to different scenarios.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra B2B collaboration settings
Why it's wrong here
Microsoft Entra B2B collaboration settings govern the invitation, redemption, domain allow/block lists, and guest invite permissions, but they do not evaluate authentication requirements at sign-in time. These settings control who can be invited and how guests access resources, not whether a guest is prompted for MFA. To enforce MFA for guests, you must use Conditional Access, which is the actual authentication control layer.
- ✗
Microsoft Entra Identity Protection user risk policy
Why it's wrong here
The Microsoft Entra Identity Protection user risk policy operates reactively by detecting risky behaviors like leaked credentials or impossible travel, and then applying remediation actions such as requiring MFA or password change when a risk level is met. It does not proactively require MFA for all guest users on every sign-in attempt, nor does it enforce MFA as a blanket policy. Since it only triggers when risk is detected, it cannot guarantee that every guest authentication is challenged with MFA.
- ✗
Microsoft Entra ID MFA registration policy
Why it's wrong here
The Microsoft Entra ID MFA registration policy ensures that users have enrolled in MFA methods (e.g., authenticator app, phone number) but it does not enforce MFA during the sign-in process. Registration is a prerequisite that enables the user to respond to an MFA prompt, yet the policy itself never blocks or challenges a sign-in. The actual enforcement—such as requiring MFA for every guest—must be applied via a Conditional Access grant control.
- ✓
Microsoft Entra Conditional Access policy
Why this is correct
A Microsoft Entra Conditional Access policy is the correct mechanism because it can target guest users—or all external identities—and apply the "Require MFA" grant control directly at each authentication attempt. You can further scope the policy to specific cloud apps, conditions, or locations, giving fine-grained enforcement. This is the standard identity-driven control for ensuring guests must complete MFA before accessing resources, making it the only option here that actually forces MFA at sign-in.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.