AZ-500 Manage identity and access Practice Question
A company has Microsoft Entra ID with Premium P2 licenses. They want to enforce Azure Multi-Factor Authentication (MFA) for all users accessing the Azure portal from untrusted networks, but only after the user has successfully entered their password. Which Conditional Access grant control should they configure?
⚠ Common exam trap
A common mix-up: candidates confuse 'Require multi-factor authentication' with 'Require device to be marked as compliant' or 'Require domain join', mistakenly thinking device state controls can enforce MFA step-up, when in fact only the MFA grant control triggers the additional authentication challenge after password entry.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require multi-factor authentication
The 'Require multi-factor authentication' grant control in Conditional Access enforces MFA after password authentication, which aligns with the requirement to prompt for MFA only after the user has successfully entered their password. This control is applied based on the condition of 'untrusted networks' (e.g., using the 'Locations' condition to target all locations except trusted IPs), ensuring that MFA is triggered specifically for Azure portal access from untrusted networks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Require multi-factor authentication
Why this is correct
The "Require multi-factor authentication" grant control, found under Access controls > Grant in a Conditional Access policy, forces the user to complete an MFA challenge (for example, an authenticator app, phone call, or hardware token) immediately after the initial password-based sign-in, blocking the session if MFA fails. This is the only option that directly enforces the stated requirement of requiring MFA after password authentication, because it specifically adds a second authentication factor rather than evaluating the device or client app state.
- ✗
Require device to be marked as compliant
Why it's wrong here
Marking a device as compliant requires the device to be enrolled in Microsoft Intune and to meet configured compliance policies such as OS version, encryption status, or jailbreak detection. This grant control evaluates the device's health and management state rather than the user's authentication strength, meaning a user could still authenticate with only a password while using a compliant device. It does not trigger any MFA challenge and therefore does not satisfy the MFA enforcement requirement.
- ✗
Require approved client app
Why it's wrong here
Requiring an approved client app restricts access to specific applications (for example, Microsoft Outlook or Microsoft Teams) that support Intune app protection policies, ensuring the app meets data-loss prevention standards. The control checks the app's identity and policy compliance, not how the user proved their identity. It can be combined with MFA in a Conditional Access policy, but on its own it does not prompt for any additional authentication step beyond the initial sign-in.
- ✗
Require domain join
Why it's wrong here
The "Require domain join" grant control demands that the device be hybrid Microsoft Entra ID joined (or, in some configurations, domain joined) to access the resource, which is a device state condition. This control validates the device's directory membership and trust relationship, not the user's authentication factor. A password-only sign-in from a domain-joined machine would still satisfy this control without ever invoking MFA, so it does not meet the requirement to enforce MFA.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.