AZ-500 Manage identity and access Practice Question
You are the Azure Security Engineer for a company that uses Microsoft Entra ID (formerly Azure AD). The security team wants to ensure that when a user signs in from an unknown location, they are required to perform multi-factor authentication (MFA). However, users signing in from the corporate office should not be prompted for MFA. You create a Conditional Access policy with a condition for trusted locations. What should you configure to ensure the policy works as intended?
⚠ Common exam trap
Many candidates confuse location-based conditions with risk-based policies or group membership, which do not evaluate real-time network location.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the corporate office public IP addresses as named locations and mark them as trusted.
The correct approach is to define named locations for the corporate office IP ranges and mark them as trusted. Conditional Access policies can then include or exclude these locations. This allows the policy to require MFA for unknown locations while exempting the trusted corporate office. Other options do not provide the necessary location-based control or are not granular enough.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable security defaults in Microsoft Entra ID to automatically require MFA for all users except those with privileged roles.
Why it's wrong here
Security defaults provide a baseline set of security settings, but they do not allow granular exceptions for trusted locations. They require MFA for all users, which would include corporate office users. This does not meet the requirement of exempting users from a specific location. Security defaults are also not customizable for such scenarios.
- ✗
Create a conditional access policy that requires MFA for all users and then exclude users who are in the corporate office by using a dynamic group.
Why it's wrong here
Dynamic groups are based on user attributes, not on location at sign-in time. You cannot dynamically group users based on their current network location. This approach would not work because group membership is not evaluated per sign-in based on IP address. Conditional Access location conditions must be used instead.
- ✗
Configure a sign-in risk policy in Microsoft Entra ID Protection to block sign-ins from unknown locations.
Why it's wrong here
Sign-in risk policies evaluate the risk level of a sign-in and can require MFA or block access. However, they are based on risk detection, not on static trusted locations. This would not reliably exempt corporate office users from MFA because risk is dynamic and may still flag legitimate sign-ins. It does not address the requirement to exclude a specific trusted location.
- ✓
Add the corporate office public IP addresses as named locations and mark them as trusted.
Why this is correct
Named locations allow you to define IP ranges that are considered trusted. By marking them as trusted, you can exclude them from the Conditional Access policy's MFA requirement. This is the correct approach because Conditional Access conditions can include location, and trusted named locations are specifically designed for this scenario. It ensures users from the corporate office are not prompted for MFA while others are.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.