AZ-500 Secure identity and access Practice Question
You are troubleshooting a sign-in issue. A user reports that they are repeatedly prompted for authentication when accessing a cloud app, even though they already authenticated earlier in the day. You check the Conditional Access policy and see that 'Session control - Sign-in frequency' is set to 1 hour. What is the most likely cause?
⚠ Common exam trap
Many candidates confuse sign-in frequency with token lifetime policies, assuming token lifetimes control reauthentication frequency, when in fact Conditional Access session controls override token lifetime settings for the specified apps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The sign-in frequency setting forces reauthentication after 1 hour
The 'Session control - Sign-in frequency' setting in Conditional Access enforces reauthentication at the specified interval. When set to 1 hour, the user must re-authenticate every hour, regardless of prior authentication earlier in the day. This explains the repeated prompts, as the session lifetime is capped by this policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The sign-in frequency setting forces reauthentication after 1 hour
Why this is correct
This is correct because in Microsoft Entra Conditional Access, the sign-in frequency session control is configured to require the user to reauthenticate after a specified time period, here 1 hour. When that interval elapses, Microsoft Entra ID forces a fresh authentication prompt even if the user's browser session and tokens are still technically valid, so the user experiences a sign-in interruption. The setting is evaluated independently of the underlying session, which explains why the user is prompted again exactly after 1 hour.
- ✗
The browser is blocking persistent cookies
Why it's wrong here
This is incorrect because while blocking persistent cookies can affect how long a user stays signed in across browser restarts, it does not control periodic reauthentication while the session is active. Sign-in frequency is enforced by Microsoft Entra Conditional Access through token claims and policy evaluation, not by cookie storage. Even if persistent cookies are blocked, Microsoft Entra ID would still allow the session to continue until the sign-in frequency interval expires; it would not trigger a reauthentication precisely at the 1-hour mark.
- ✗
Token lifetime policy overrides the sign-in frequency
Why it's wrong here
This is incorrect because token lifetime policies determine the maximum validity of access or refresh tokens, but they do not override the Conditional Access sign-in frequency control. Sign-in frequency can force a reauthentication earlier than the token lifetime, because it is evaluated separately during each token request against the configured time window. In this scenario, the 1-hour reauthentication is the direct result of the sign-in frequency setting, not an artifact of token expiration or policy precedence.
- ✗
The user is considered high risk by Identity Protection
Why it's wrong here
This is incorrect because Identity Protection risk-based Conditional Access policies trigger only when a user's risk level is elevated, and they typically respond by requiring MFA, blocking sign-in, or requiring a password change—not by simply demanding reauthentication at a fixed interval. There is no mention of a risk detection, so attributing the prompt to risk would be unfounded. The fixed 1-hour cadence is a hallmark of sign-in frequency, not a risk-based policy.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.