Courseiva
Manage identity and access →mediumMultiple Choice

AZ-500 Manage identity and access Practice Question

A company uses Microsoft Entra Conditional Access. They want to require multi-factor authentication (MFA) for all users accessing the Azure portal, but only when the sign-in risk level is medium or above. Which configuration should they use in the Conditional Access policy?

⚠ Common exam trap

Many exam-takers confuse 'User risk' with 'Sign-in risk' — user risk is a persistent score based on past user behavior, while sign-in risk is a session-level assessment, and the question explicitly requires the latter for the current sign-in event.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assignments > Cloud apps > Include > Microsoft Azure Management, Conditions > Sign-in risk > Medium and above, Grant > Require MFA.

It specifically targets the Azure portal via 'Microsoft Azure Management' in Cloud apps, sets the sign-in risk condition to 'Medium and above', and requires MFA. This matches the requirement exactly: MFA is triggered only when accessing the Azure portal and the sign-in risk level is medium or higher.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Assignments > Cloud apps > Include > Microsoft Azure Management, Conditions > Sign-in risk > Medium and above, Grant > Require MFA.

    Why this is correct

    This is correct because the Microsoft Azure Management cloud app encompasses the Azure portal, Azure Resource Manager, CLI, and PowerShell, so the policy applies to administrative control-plane sign-ins. Adding the Sign-in risk condition at 'Medium and above' causes Microsoft Entra ID Protection to evaluate the current authentication attempt for real-time risk, and the Grant control forces MFA when that risk threshold is met. This narrowly targets Azure management rather than all cloud apps, which is exactly what the company needs.

  • ✗

    Assignments > Users > All users, Cloud apps > All cloud apps, Conditions > User risk > Medium, Grant > Require MFA.

    Why it's wrong here

    This is incorrect because the User risk condition evaluates whether the user account has been compromised based on previous risky activity, not whether the current sign-in itself is risky. Including 'All cloud apps' widens the policy to every application, whereas the company only needs MFA for Azure management. User risk also lags behind real-time events, so it does not provide the same immediate signal as Sign-in risk for a current Azure portal logon.

  • ✗

    Assignments > Conditions > Locations > All trusted locations, Grant > Require MFA.

    Why it's wrong here

    Location-based conditions, including All trusted locations, use the originating IP or named-location state, not risk signals from the actual authentication. A trusted location policy either explicitly requires or exempts MFA based on where a user connects, and it has no Cloud apps assignment in this fragment, so it would not be limited to Microsoft Azure Management. Requiring MFA from trusted locations is not the same as requiring MFA only when sign-in risk is Medium and above, so this leaves risky sign-ins from untrusted networks unaffected.

  • ✗

    Assignments > Cloud apps > Include > All cloud apps, Conditions > Device platforms > iOS, Grant > Require MFA.

    Why it's wrong here

    Device platform restrictions apply only after the user's device platform is known and do not incorporate any risk assessment from Identity Protection. Targeting All cloud apps and iOS would force MFA only when an iOS device accesses any app, so it both over-reaches beyond Azure management and misses risky sign-ins from Windows, Android, or other platforms. This policy would not satisfy the requirement to gate the Azure portal on sign-in risk.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.