Courseiva
Secure identity and access →mediumMultiple Choice

AZ-500 Secure identity and access Practice Question

You are a security engineer for a company that uses Microsoft Entra ID. The company has a policy that users must sign in using Windows Hello for Business or a FIDO2 security key. You need to block legacy authentication protocols that do not support these methods. What should you configure?

⚠ Common exam trap

Test-takers frequently confuse security defaults or authentication method policies with the granular control needed to block legacy authentication while allowing modern methods.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Conditional Access policy that targets all users and all cloud apps, and set the client apps condition to 'Exchange ActiveSync clients' and 'Other clients', then set access control to 'Block'.

To block legacy authentication, you must use Conditional Access to target client apps that use legacy protocols. The 'Exchange ActiveSync clients' and 'Other clients' conditions specifically cover clients that do not support modern authentication. Setting the access control to 'Block' ensures these clients cannot sign in. Other options do not directly block legacy protocols; they address different security aspects such as risk, baseline defaults, or authentication methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable security defaults in Microsoft Entra ID.

    Why it's wrong here

    Security defaults provide a baseline set of security settings, including requiring MFA for all users and blocking legacy authentication. However, they are a broad, one-size-fits-all policy that cannot be customized to target specific users or apps, and they may conflict with existing Conditional Access policies. The requirement is to specifically block legacy authentication while allowing modern methods, which is better achieved with Conditional Access.

  • ✗

    Create an authentication method policy that disables SMS and voice call methods.

    Why it's wrong here

    Authentication method policies control which methods users can register and use for multi-factor authentication, such as SMS, voice call, or Microsoft Authenticator. Disabling SMS and voice call does not block legacy authentication protocols; legacy protocols can still be used with other methods. This does not address the need to prevent clients that do not support Windows Hello for Business or FIDO2.

  • ✓

    Create a Conditional Access policy that targets all users and all cloud apps, and set the client apps condition to 'Exchange ActiveSync clients' and 'Other clients', then set access control to 'Block'.

    Why this is correct

    This correctly blocks legacy authentication protocols because 'Exchange ActiveSync clients' and 'Other clients' represent legacy clients that do not support modern authentication. By targeting all users and cloud apps and blocking these client types, you prevent sign-ins that cannot enforce Windows Hello for Business or FIDO2. This is the recommended approach in Microsoft Entra ID to eliminate legacy authentication.

  • ✗

    Configure a sign-in risk policy in Microsoft Entra ID Protection to block sign-ins with medium or high risk.

    Why it's wrong here

    Sign-in risk policies evaluate the risk level of a sign-in based on signals like anonymous IP addresses or atypical travel. They do not block legacy authentication protocols specifically. While they can add protection, they do not prevent clients that use basic authentication from attempting to sign in. Therefore, this does not meet the requirement to block legacy protocols.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.