AZ-500 Manage identity and access Practice Question
A company uses Microsoft Entra ID and has guest users invited via B2B collaboration. The security team wants to require that all guest users from specific external organizations must complete multi-factor authentication (MFA) when accessing the company's SaaS applications. Which Conditional Access policy configuration should they use?
⚠ Common exam trap
A common mix-up: candidates confuse the broad 'Guest or external users' identity with the granular 'External tenants' condition, mistakenly thinking that selecting 'Guest or external users' alone is sufficient to scope MFA to specific organizations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a policy that applies to 'Guest or external users' with a condition for 'External tenants' specifying the organizations, and a grant control of 'Require multi-factor authentication'.
It uses the 'External tenants' condition within a Conditional Access policy targeting 'Guest or external users' to specify the exact organizations from which guests must complete MFA. This directly meets the requirement to scope MFA enforcement to specific external organizations, not all guests. The 'Require multi-factor authentication' grant control ensures MFA is enforced for those guests when accessing SaaS applications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a policy that applies to 'All users' with a condition for 'Guest or external users' and a grant control of 'Require multi-factor authentication'.
Why it's wrong here
This policy is incorrectly scoped because 'All users' includes every internal identity, not just guests. In Microsoft Entra Conditional Access, 'Guest or external users' is not a separate condition you add to a broad scope; it is itself a selectable assignment scope. By choosing 'All users' and then attempting to condition on guest type, the policy would actually be evaluated against all users, forcing internal employees to undergo MFA even though the requirement only targets guests. That unnecessarily expands the policy surface and could cause sign-in failures or excessive MFA prompts for staff, so it does not meet the precise requirement.
- ✓
Create a policy that applies to 'Guest or external users' with a condition for 'External tenants' specifying the organizations, and a grant control of 'Require multi-factor authentication'.
Why this is correct
This is the correct approach in Microsoft Entra Conditional Access. By setting the assignment to 'Guest or external users' and adding a condition for 'External tenants' with specific organization IDs, you narrowly and explicitly target only guest users from those partner tenants. The grant control 'Require multi-factor authentication' then enforces MFA at sign-in, which is exactly the stated requirement. This policy avoids affecting internal users and does not rely on risk signals or session-based restrictions, so it fulfills the policy objective with the least disruption.
- ✗
Create a policy that applies to 'All guest users' and assign it to the SaaS applications. Use a session control 'Use app enforced restrictions'.
Why it's wrong here
This option confuses a session control with a grant control. 'Use app enforced restrictions' is a Conditional Access session control that works with cloud app security or app-enforced policies to limit actions inside an app (for example, restricting download or copy), but it does not require multi-factor authentication during sign-in. Grant controls are the only way to enforce MFA as a condition of access. Additionally, assigning to 'All guest users' would include all external identities, not just specific organizations, so even if it were a grant control, it would be too broad in tenant scope and still would not enforce MFA.
- ✗
Create a policy that applies to 'Guest or external users' with a condition for 'Sign-in risk' set to 'Medium and above' and a grant control of 'Block access'.
Why it's wrong here
This policy fails because it is conditional on 'Sign-in risk' rather than requiring MFA for every guest user from the specified tenants. Setting risk to 'Medium and above' with 'Block access' only triggers a block when Microsoft Entra ID detects a risky sign-in pattern, so a guest user with low or no risk would be allowed without MFA. The requirement is to require MFA for all guest users from those organizations, not just risky ones. Furthermore, 'Block access' denies the sign-in outright when risk is high, whereas the requirement asks for MFA as an additional authentication step, not a blanket blockage.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.