Courseiva

AZ-500 Secure identity and access Practice Question

You are configuring a conditional access policy to block access from untrusted locations. The policy should apply to all cloud apps except Microsoft Entra ID Administration. How should you configure the policy?

⚠ Common exam trap

Test-takers frequently confuse 'Microsoft Entra ID Administration' with 'Office 365' or think they must manually select all apps, missing the efficient 'All cloud apps' plus exclusion pattern.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Include 'All cloud apps' and exclude 'Microsoft Entra ID Administration'

The requirement is to block access from untrusted locations for all cloud apps except Microsoft Entra ID Administration. In Conditional Access, you include 'All cloud apps' to cover every app, then explicitly exclude 'Microsoft Entra ID Administration' to exempt it from the block. This ensures the policy applies broadly while honoring the exclusion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Include 'All cloud apps' and set 'Block access'

    Why it's wrong here

    Including all cloud apps with Block access also blocks Microsoft Entra ID Administration, which the scenario explicitly exempts. It is tempting because blocking untrusted locations is the stated goal, yet the policy must carve out the admin portal, so an exclusion is required alongside the block.

  • ✗

    Include 'Select apps' and choose all apps except admin

    Why it's wrong here

    Selecting apps individually omits newly added cloud apps, so coverage is incomplete and administration cannot be cleanly excluded. It is tempting because it appears to target only the intended apps, but the requirement is all apps except one, which the include-all-with-exclusion model handles.

  • ✓

    Include 'All cloud apps' and exclude 'Microsoft Entra ID Administration'

    Why this is correct

    Conditional access evaluates include and exclude scopes, with exclusions taking precedence. Selecting 'All cloud apps' as the include and excluding 'Microsoft Entra ID Administration' satisfies the requirement to block untrusted locations everywhere except administrative access, avoiding the need to enumerate every individual app.

  • ✗

    Include 'All cloud apps' and exclude 'Office 365'

    Why it's wrong here

    Excluding Office 365 leaves Microsoft Entra ID Administration included and blocked, so administrators lose access, contrary to the requirement. It is tempting because Office 365 is a common exclusion for app-specific policies, but the stem requires excluding the administration portal, not the productivity suite.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.