AZ-500 Secure identity and access Practice Question
Exhibit
Refer to the exhibit.
{
"policy": {
"displayName": "Block legacy authentication",
"state": "enabledForReportingButNotEnforced",
"conditions": {
"clientAppTypes": ["exchangeActiveSync", "otherClients"],
"applications": {
"includeApplications": ["Office365"]
}
},
"grantControls": {
"builtInControls": ["block"]
}
}
}You have configured the Conditional Access policy shown in the exhibit. Users report that they can still access Exchange Online using legacy authentication protocols. What is the most likely reason?
⚠ Common exam trap
The trap here is that candidates often overlook the policy state setting and focus on grant controls or client app types, assuming a 'Block' control is always enforced, but Microsoft Entra ID's reporting mode explicitly disables enforcement regardless of other configurations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy state is set to reporting mode
The policy state is set to 'Report-only' (reporting mode), which means the Conditional Access policy is evaluated but not enforced. Users can still access Exchange Online using legacy authentication because the policy only logs the outcome without blocking access. To enforce the block, the policy state must be set to 'On'.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy should use 'Require MFA' instead of 'Block'
Why it's wrong here
The policy's assignment and conditions are appropriately targeting the risky sign-in scenario, and a Block control is a valid remediation. The core misconfiguration is not the control itself; a report-only policy does not enforce any access controls, whether Block or Require MFA, so switching to Require MFA would still only produce a report and fail to prevent access. Changing the control would not fix the lack of enforcement.
- ✗
The policy does not include the correct client app types
Why it's wrong here
The client apps configuration already includes Exchange ActiveSync and otherClients, which are exactly the categories used for legacy authentication protocols such as basic authentication for Exchange Online and other older clients. There is no missing client app type in this policy; the block would apply to both modern and legacy clients once the policy is actually enforced. The inability to block is caused by the policy being in report-only mode, not by a gap in the client app selection.
- ✓
The policy state is set to reporting mode
Why this is correct
Conditional Access policies in report-only mode (also called reporting mode) are evaluated against the conditions and the result is logged in the sign-in logs, but the configured access controls are never applied. As a result, a Block control will not prevent the user from accessing the resource; the policy only emits a 'reportOnly: failure' entry. To enforce the block, the policy state must be set to 'Enabled' (or 'On'), which applies the Block control during authentication. This is the direct reason why the block is not in effect.
- ✗
The policy should include 'mobileAppsAndDesktopClients' instead
Why it's wrong here
This option misidentifies the relevant client app category: 'Mobile apps and desktop clients' is for clients using modern authentication, while the policy needs to cover legacy clients that use basic protocols, which are represented by 'Other clients' and Exchange ActiveSync. The policy already includes the correct client app types for the legacy authentication scenario, so replacing them with mobileAppsAndDesktopClients would not improve coverage. Even if the client app type were changed, the policy would remain non-enforcing because it is in report-only mode, so this is not the cause of the problem.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.