AZ-500 Secure identity and access Practice Question
You are a security engineer for a company that uses Microsoft Entra ID. The company has a policy that users must sign in using Windows Hello for Business or a FIDO2 security key. You need to block legacy authentication protocols that do not support these methods. What should you configure?
⚠ Common exam trap
Test-takers frequently confuse security defaults or authentication method policies with the granular control needed to block legacy authentication while allowing modern methods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy that targets all users and all cloud apps, and set the client apps condition to 'Exchange ActiveSync clients' and 'Other clients', then set access control to 'Block'.
To block legacy authentication, you must use Conditional Access to target client apps that use legacy protocols. The 'Exchange ActiveSync clients' and 'Other clients' conditions specifically cover clients that do not support modern authentication. Setting the access control to 'Block' ensures these clients cannot sign in. Other options do not directly block legacy protocols; they address different security aspects such as risk, baseline defaults, or authentication methods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable security defaults in Microsoft Entra ID.
Why it's wrong here
Security defaults provide a baseline set of security settings, including requiring MFA for all users and blocking legacy authentication. However, they are a broad, one-size-fits-all policy that cannot be customized to target specific users or apps, and they may conflict with existing Conditional Access policies. The requirement is to specifically block legacy authentication while allowing modern methods, which is better achieved with Conditional Access.
- ✗
Create an authentication method policy that disables SMS and voice call methods.
Why it's wrong here
Authentication method policies control which methods users can register and use for multi-factor authentication, such as SMS, voice call, or Microsoft Authenticator. Disabling SMS and voice call does not block legacy authentication protocols; legacy protocols can still be used with other methods. This does not address the need to prevent clients that do not support Windows Hello for Business or FIDO2.
- ✓
Create a Conditional Access policy that targets all users and all cloud apps, and set the client apps condition to 'Exchange ActiveSync clients' and 'Other clients', then set access control to 'Block'.
Why this is correct
This correctly blocks legacy authentication protocols because 'Exchange ActiveSync clients' and 'Other clients' represent legacy clients that do not support modern authentication. By targeting all users and cloud apps and blocking these client types, you prevent sign-ins that cannot enforce Windows Hello for Business or FIDO2. This is the recommended approach in Microsoft Entra ID to eliminate legacy authentication.
- ✗
Configure a sign-in risk policy in Microsoft Entra ID Protection to block sign-ins with medium or high risk.
Why it's wrong here
Sign-in risk policies evaluate the risk level of a sign-in based on signals like anonymous IP addresses or atypical travel. They do not block legacy authentication protocols specifically. While they can add protection, they do not prevent clients that use basic authentication from attempting to sign in. Therefore, this does not meet the requirement to block legacy protocols.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.