Courseiva
Secure identity and access →mediumMultiple Select

AZ-500 Secure identity and access Practice Question

Which TWO of the following are methods to enforce MFA in Microsoft Entra ID?

⚠ Common exam trap

Many exam-takers confuse Identity Protection user risk policy (Option A) as a direct MFA enforcement method, but it only detects risk and requires a Conditional Access policy to actually enforce MFA as a control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security defaults

Security defaults (C) is correct because it is a Microsoft-managed baseline that, once enabled, automatically requires all users to register for MFA and enforces MFA for privileged actions such as Azure portal, Microsoft Entra admin center, and Azure CLI/PowerShell access. Conditional Access policy (D) is correct because it is the primary granular method to enforce MFA, letting you create a policy that targets users/groups and cloud apps with a Grant control of 'Require multifactor authentication' (optionally combined with conditions like sign-in risk, location, or device state). Identity Protection user risk policy (A) does not itself enforce MFA; it can require a password change or, in some configurations, allow access, and MFA enforcement is typically achieved by pairing risk signals with a Conditional Access grant control. Password Protection (B) only blocks weak or banned passwords via custom banned password lists and does not perform MFA. Self-service password reset (E) is a credential-reset feature and does not enforce MFA, even though it may require MFA as an authentication method for the reset process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Identity Protection user risk policy

    Why it's wrong here

    Identity Protection user risk policy is a risk-based conditional policy that triggers MFA only when a user's risk level is evaluated as medium or high during sign-in. It does not enforce MFA for every authentication attempt, so it is a reactive control based on detected risk rather than a direct, always-on MFA enforcement method.

  • ✗

    Password Protection

    Why it's wrong here

    Password Protection is an Microsoft Entra ID feature that blocks weak, leaked, or commonly used passwords by evaluating password changes and resets against a banned list. It focuses entirely on password strength and does not require or enforce any form of multi-factor authentication, so it cannot be considered an MFA enforcement method.

  • ✓

    Security defaults

    Why this is correct

    Security defaults provide a predefined baseline of security settings that automatically enforce MFA for all users, requiring registration through the Microsoft Authenticator app and blocking legacy authentication protocols. This is a mandatory, tenant-wide enforcement mechanism that is enabled by default for new tenants, making it a direct and comprehensive method to enforce MFA.

  • ✓

    Conditional Access policy

    Why this is correct

    Conditional Access policy is a granular, policy-based engine that can require MFA as a grant control when specific conditions are met, such as user membership, location, device state, or application. By dynamically evaluating each sign-in and enforcing MFA based on configured conditions, it is a flexible and direct method to enforce MFA beyond a simple global setting.

  • ✗

    Self-service password reset

    Why it's wrong here

    Self-service password reset allows users to reset their own passwords by validating one or more authentication methods such as security questions, email, or phone; it does not require MFA for normal sign-in or for the reset process itself. Because it is designed for password recovery and not for authenticating access to resources, it is not an MFA enforcement mechanism.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.