AZ-500 Manage identity and access Practice Question
A company has Microsoft Entra Conditional Access policies that require multi-factor authentication (MFA) for all users accessing sensitive cloud apps. The security team wants to extend this protection by monitoring and controlling user activities within those applications (e.g., preventing data exfiltration during a session). Which Conditional Access session control should they implement?
⚠ Common exam trap
Watch out — candidates often confuse session controls that manage sign-in frequency or app-enforced restrictions with the more advanced session monitoring and data exfiltration prevention capabilities provided by Conditional Access Application Control, which is the only option that offers real-time in-app activity control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session control: Conditional Access Application Control
Conditional Access Application Control (also known as Microsoft Defender for Cloud Apps session control) allows real-time monitoring and control of user activities within cloud apps, such as blocking downloads or preventing data exfiltration. This session control works by redirecting user traffic through Microsoft Defender for Cloud Apps as a reverse proxy, enabling granular policy enforcement during the session. The requirement specifically asks for monitoring and controlling activities inside the app, which goes beyond just requiring MFA at sign-in.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant control: Require MFA
Why it's wrong here
Require MFA is a grant control that only enforces strong authentication at the time of sign-in, not a session control. It verifies the user's identity but provides no visibility into or ability to restrict actions they perform after authentication, such as downloading files or accessing sensitive data. Therefore, it cannot satisfy a require monitoring and controlling in-session activities scenario.
- ✗
Session control: Use app enforced restrictions
Why it's wrong here
The 'Use app enforced restrictions' session control delegates session-level security to the application itself (e.g., SharePoint Online redirection for managed devices). While it can restrict actions, it depends entirely on the app's native capabilities and does not give a centralized, real-time view of sessions across all SaaS apps from one admin pane. It lacks the comprehensive monitoring and granular controls, like blocking specific activities, that Conditional Access Application Control provides.
- ✗
Session control: Sign-in frequency
Why it's wrong here
The 'Sign-in frequency' session control forces reauthentication after a defined interval, effectively setting a maximum token lifetime. This is a time-based control that interrupts the session periodically, but it does not monitor or restrict in-session activities in real time. It merely forces the user to re-authenticate; it cannot detect or block a malicious action like a mass download that occurs between sign-ins.
- ✓
Session control: Conditional Access Application Control
Why this is correct
Conditional Access Application Control is the correct session control because it integrates with Microsoft Defender for Cloud Apps to route sessions through a reverse proxy, enabling real-time monitoring and policy enforcement. Administrators can apply granular actions such as blocking downloads, restricting access, or applying data protection policies dynamically based on user and risk context. This provides the centralized, in-session activity monitoring and control that the scenario specifically requires.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.