Courseiva
Secure identity and access →mediumMultiple Choice

AZ-500 Secure identity and access Practice Question

You are the security administrator for a company that uses Microsoft Entra ID. You need to configure a Conditional Access policy that applies to all users except the emergency break-glass accounts. The policy must require multi-factor authentication (MFA) when accessing the Azure portal from a location that is not trusted. What should you include in the policy?

⚠ Common exam trap

The trap here is that candidates often forget to include the 'Locations' condition to scope the MFA requirement to untrusted locations, leading them to choose Option D which requires MFA for all Azure portal access, not just from untrusted locations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Include all users, exclude break-glass accounts, require MFA for Azure portal, and use 'Locations' condition to specify untrusted locations

It includes all users, excludes the emergency break-glass accounts to ensure they remain accessible during outages, requires MFA for the Azure portal, and uses the 'Locations' condition to target untrusted locations. This configuration aligns with the requirement to enforce MFA only when accessing Azure portal from untrusted locations, while preserving access for break-glass accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Include all users, exclude break-glass accounts, require MFA for Azure portal, and use 'Locations' condition to specify untrusted locations

    Why this is correct

    This configuration is correct because it precisely implements the stated requirement: the policy includes every user, explicitly excludes break-glass accounts to preserve emergency access, triggers on the Azure portal cloud app, and uses the Conditions > Locations element to scope MFA to untrusted public networks. By selecting 'Any location' except trusted IPs, the policy will prompt for MFA only when a user signs in from outside the corporate network, avoiding excessive prompts on trusted IP ranges. This matches the directive to require MFA for all users except emergency access accounts from untrusted locations.

  • ✗

    Include all users, require MFA for Azure portal, and exclude all administrators

    Why it's wrong here

    Excluding all administrators from the Conditional Access policy removes MFA from the exact accounts that are most likely to be targeted by attackers and that have the broadest access to Azure portal. An admin account compromised with only a password would be catastrophic, so admins should be the first group required to use MFA, not the exception. Additionally, the policy is not scoped by location, meaning it would require MFA from every network, which contradicts the goal of only requiring MFA from untrusted locations.

  • ✗

    Include break-glass accounts, require MFA for Azure portal, and block access from untrusted locations

    Why it's wrong here

    Break-glass accounts must never be included in a Conditional Access policy that requires MFA or blocks access, since they exist specifically to grant access when normal identity controls are unavailable. Blocking access from untrusted locations is far more aggressive than the requirement, which only calls for an MFA challenge, and could prevent legitimate sign-ins from hotel or public networks. The correct approach is to exclude break-glass accounts and use the locations condition to require MFA, not to block the session entirely.

  • ✗

    Include all users, require MFA for Azure portal, and exclude break-glass accounts

    Why it's wrong here

    Including all users and requiring MFA is correct, but the exclusion of break-glass accounts is not mentioned in the stem as a separate condition; the stem already says 'all users except break-glass accounts' so the policy should explicitly exclude them.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.