Courseiva
Secure identity and access →mediumMultiple Choice

AZ-500 Conditional Access policy JSON Practice Question

Exhibit

Refer to the exhibit.

{
  "tenantId": "contoso.onmicrosoft.com",
  "authenticationStrength": {
    "allowedAuthMethods": ["password", "mfa"],
    "requireMfa": true
  },
  "conditions": {
    "applications": {
      "includeApplications": ["Office365"]
    },
    "users": {
      "includeUsers": ["all"]
    }
  },
  "grantControls": {
    "builtInControls": ["mfa"],
    "termsOfUse": [],
    "customAuthenticationFactors": []
  }
}

Refer to the exhibit. You are analyzing a Conditional Access policy JSON. The policy requires MFA for Office 365 applications. However, users report that they are still able to access Office 365 without MFA. What is the most likely reason?

⚠ Common exam trap

Candidates often overlook that an empty 'grantControls' section means no controls are enforced. The policy appears structurally correct but fails to apply any requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The 'grantControls' section is empty

The most likely reason is that the 'grantControls' section is empty. In a Conditional Access policy, the 'grantControls' section specifies the controls to enforce, such as requiring MFA. If this section is empty, no controls are applied, and users can access Office 365 without MFA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The policy excludes some Office 365 apps

    Why it's wrong here

    The policy could exclude some Office 365 apps, but that would only allow access to those specific apps without MFA, not all Office 365 apps. The question states users can access Office 365 without MFA, implying the policy is not enforced at all, which is more likely due to empty grantControls.

  • ✓

    The 'grantControls' section is empty

    Why this is correct

    Grant controls define what the policy enforces. With an empty grantControls section, no access requirement such as require multifactor authentication is applied, so the policy evaluates as satisfied and users reach Office 365 without completing MFA.

  • ✗

    The 'authenticationStrength' property is not a valid Conditional Access policy property

    Why it's wrong here

    Authentication strength is a valid Conditional Access property controlling which MFA methods satisfy a grant. The reported behaviour stems from policy scope, such as exclusions, report-only state, or a missing grant control, so blaming the schema misdirects troubleshooting. Authentication strength is used when specific phishing-resistant methods must be enforced.

  • ✗

    The policy does not include all users

    Why it's wrong here

    If the policy does not include all users, some users would be exempt, but the question implies users in general (likely all users) are able to access without MFA, suggesting the policy is not applying to anyone, which points to empty grantControls.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.