AZ-500 Manage identity and access Practice Question
You are the Azure Security Engineer for a company that uses Microsoft Entra ID. The company has a policy that all administrative accounts must use multi-factor authentication (MFA) when signing in. You need to enforce this policy for a group of administrators. What is the simplest way to achieve this?
⚠ Common exam trap
The trap here is choosing security defaults or per-user MFA, which are either too broad or too manual, instead of the targeted Conditional Access policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy that requires MFA for the administrator group when accessing all cloud apps.
The simplest way to enforce MFA for a specific group of administrators is to create a Conditional Access policy that targets that group and requires MFA for all cloud apps. This provides granular control and is easy to manage. Other options either apply to all users, require manual per-user settings, or are risk-based rather than always-on.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a Conditional Access policy that requires MFA for the administrator group when accessing all cloud apps.
Why this is correct
A Conditional Access policy can be targeted to a specific group of administrators and require MFA for all cloud apps. This is the simplest and most direct method to enforce MFA for that group. It provides granular control and can be easily managed. This meets the requirement without affecting other users.
- ✗
Configure per-user MFA for each administrator account.
Why it's wrong here
Per-user MFA is a legacy feature that requires manual configuration for each user. It is not as flexible or manageable as Conditional Access, especially for a group. It also does not provide the same level of control and reporting. For a group of administrators, this approach is cumbersome and not the simplest.
- ✗
Enable security defaults in Microsoft Entra ID.
Why it's wrong here
Security defaults enforce MFA for all users, not just administrators. While this would meet the requirement for administrators, it would also affect all other users, which may not be desired. Security defaults are a baseline and do not allow granular targeting. The scenario asks for the simplest way for a specific group, so this is overreaching.
- ✗
Create a Microsoft Entra ID Protection sign-in risk policy that requires MFA for administrators.
Why it's wrong here
Sign-in risk policies trigger MFA based on detected risk, not as a blanket requirement for a group. This would not enforce MFA for all sign-ins by administrators, only those deemed risky. The requirement is to always require MFA for administrative accounts, so this does not meet the need. It is also more complex than necessary.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.