AZ-500 Conditional Access policy JSON Practice Question
Exhibit
Refer to the exhibit.
{
"tenantId": "contoso.onmicrosoft.com",
"authenticationStrength": {
"allowedAuthMethods": ["password", "mfa"],
"requireMfa": true
},
"conditions": {
"applications": {
"includeApplications": ["Office365"]
},
"users": {
"includeUsers": ["all"]
}
},
"grantControls": {
"builtInControls": ["mfa"],
"termsOfUse": [],
"customAuthenticationFactors": []
}
}Refer to the exhibit. You are analyzing a Conditional Access policy JSON. The policy requires MFA for Office 365 applications. However, users report that they are still able to access Office 365 without MFA. What is the most likely reason?
⚠ Common exam trap
Candidates often overlook that an empty 'grantControls' section means no controls are enforced. The policy appears structurally correct but fails to apply any requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The 'grantControls' section is empty
The most likely reason is that the 'grantControls' section is empty. In a Conditional Access policy, the 'grantControls' section specifies the controls to enforce, such as requiring MFA. If this section is empty, no controls are applied, and users can access Office 365 without MFA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy excludes some Office 365 apps
Why it's wrong here
The policy could exclude some Office 365 apps, but that would only allow access to those specific apps without MFA, not all Office 365 apps. The question states users can access Office 365 without MFA, implying the policy is not enforced at all, which is more likely due to empty grantControls.
- ✓
The 'grantControls' section is empty
Why this is correct
Grant controls define what the policy enforces. With an empty grantControls section, no access requirement such as require multifactor authentication is applied, so the policy evaluates as satisfied and users reach Office 365 without completing MFA.
- ✗
The 'authenticationStrength' property is not a valid Conditional Access policy property
Why it's wrong here
Authentication strength is a valid Conditional Access property controlling which MFA methods satisfy a grant. The reported behaviour stems from policy scope, such as exclusions, report-only state, or a missing grant control, so blaming the schema misdirects troubleshooting. Authentication strength is used when specific phishing-resistant methods must be enforced.
- ✗
The policy does not include all users
Why it's wrong here
If the policy does not include all users, some users would be exempt, but the question implies users in general (likely all users) are able to access without MFA, suggesting the policy is not applying to anyone, which points to empty grantControls.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.