AZ-500 Secure identity and access Practice Question
Which TWO of the following are methods to enforce MFA in Microsoft Entra ID?
⚠ Common exam trap
Many exam-takers confuse Identity Protection user risk policy (Option A) as a direct MFA enforcement method, but it only detects risk and requires a Conditional Access policy to actually enforce MFA as a control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security defaults
Security defaults (C) is correct because it is a Microsoft-managed baseline that, once enabled, automatically requires all users to register for MFA and enforces MFA for privileged actions such as Azure portal, Microsoft Entra admin center, and Azure CLI/PowerShell access. Conditional Access policy (D) is correct because it is the primary granular method to enforce MFA, letting you create a policy that targets users/groups and cloud apps with a Grant control of 'Require multifactor authentication' (optionally combined with conditions like sign-in risk, location, or device state). Identity Protection user risk policy (A) does not itself enforce MFA; it can require a password change or, in some configurations, allow access, and MFA enforcement is typically achieved by pairing risk signals with a Conditional Access grant control. Password Protection (B) only blocks weak or banned passwords via custom banned password lists and does not perform MFA. Self-service password reset (E) is a credential-reset feature and does not enforce MFA, even though it may require MFA as an authentication method for the reset process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Identity Protection user risk policy
Why it's wrong here
Identity Protection user risk policy is a risk-based conditional policy that triggers MFA only when a user's risk level is evaluated as medium or high during sign-in. It does not enforce MFA for every authentication attempt, so it is a reactive control based on detected risk rather than a direct, always-on MFA enforcement method.
- ✗
Password Protection
Why it's wrong here
Password Protection is an Microsoft Entra ID feature that blocks weak, leaked, or commonly used passwords by evaluating password changes and resets against a banned list. It focuses entirely on password strength and does not require or enforce any form of multi-factor authentication, so it cannot be considered an MFA enforcement method.
- ✓
Security defaults
Why this is correct
Security defaults provide a predefined baseline of security settings that automatically enforce MFA for all users, requiring registration through the Microsoft Authenticator app and blocking legacy authentication protocols. This is a mandatory, tenant-wide enforcement mechanism that is enabled by default for new tenants, making it a direct and comprehensive method to enforce MFA.
- ✓
Conditional Access policy
Why this is correct
Conditional Access policy is a granular, policy-based engine that can require MFA as a grant control when specific conditions are met, such as user membership, location, device state, or application. By dynamically evaluating each sign-in and enforcing MFA based on configured conditions, it is a flexible and direct method to enforce MFA beyond a simple global setting.
- ✗
Self-service password reset
Why it's wrong here
Self-service password reset allows users to reset their own passwords by validating one or more authentication methods such as security questions, email, or phone; it does not require MFA for normal sign-in or for the reset process itself. Because it is designed for password recovery and not for authenticating access to resources, it is not an MFA enforcement mechanism.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.