Courseiva

AZ-500 Secure identity and access Practice Question

Your company has a Microsoft Entra ID tenant with 10,000 users. You need to implement a secure authentication strategy that satisfies the following requirements: - Users must not be able to bypass security verification using alternate authentication methods. - Passwordless authentication should be used where possible. - Legacy authentication protocols must be blocked.

Which THREE actions should you take? (Choose three.)

⚠ Common exam trap

It's easy for candidates to assume Security defaults is the simplest way to block legacy authentication and enforce MFA, but they overlook that Security defaults cannot be customized to selectively enable FIDO2 or disable specific methods, making it incompatible with the requirement for passwordless authentication and granular control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Conditional Access policy to block legacy authentication protocols.

Option A is correct because a Conditional Access policy targeting the 'Other clients' client apps condition (which covers legacy protocols such as IMAP, POP3, SMTP AUTH, and older Office clients) is the supported way to block legacy authentication in Microsoft Entra ID. Option C is correct because enabling the FIDO2 security key authentication method and configuring it for passwordless sign-in provides a phishing-resistant, passwordless credential that satisfies the passwordless requirement. Option E is correct because disabling SMS and voice call methods removes weaker alternate authentication methods that users could otherwise use to bypass stronger security verification, directly addressing the no-bypass requirement. Option B is not correct because per-user MFA is a legacy, always-on setting that cannot enforce method restrictions or passwordless flows and does not block legacy authentication. Option D is not correct because Security defaults are a baseline for tenants without Conditional Access and cannot be combined with the granular Conditional Access policy needed here, nor do they enforce passwordless authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a Conditional Access policy to block legacy authentication protocols.

    Why this is correct

    Conditional Access policies operate at the authentication plane and allow granular control based on client app, IP, and risk. By targeting 'Other clients' and explicitly selecting 'Block access,' you can deny legacy protocols like POP3, IMAP4, and SMTP AUTH that bypass modern authentication and MFA, effectively closing known attack vectors for password-spraying and credential-stuffing. This is the most direct and policy-driven method to prohibit these insecure sign-ins across all users and apps.

  • ✗

    Configure per-user MFA to require verification.

    Why it's wrong here

    Per-user MFA, configured via the legacy MFA portal, forces an additional verification step but does not prevent protocols that ignore the prompt; legacy authentication clients simply do not honor the MFA challenge, so credentials are still accepted. Moreover, per-user settings lack the conditional context (location, device compliance, risk) available in Conditional Access and can degrade the sign-in experience compared to modern authentication policies. It also forces MFA for every interaction, including service accounts, leading to potential lockouts or excessive friction.

  • ✓

    Enable FIDO2 security keys as an authentication method and configure passwordless sign-in.

    Why this is correct

    FIDO2 security keys provide phishing-resistant, passwordless authentication using public-key cryptography, eliminating shared secrets entirely. Enabling this method in Microsoft Entra ID and configuring passwordless sign-in increases overall authentication security by requiring a hardware-bound key, but it does not block legacy protocols—those clients still attempt password-based logins. As a result, while FIDO2 is a strong defense for interactive modern-auth sign-ins, it must be paired with a Conditional Access policy that blocks legacy authentication to fully address the requirement.

  • ✗

    Enable the 'Security defaults' feature in Microsoft Entra ID.

    Why it's wrong here

    Security defaults automatically enforce baseline policies, including tenant-wide MFA and blocking legacy authentication, but it is a blunt instrument that applies to all users with no exclusions or granular controls. It blocks only certain legacy authentication flows for administrative users and cannot be customized for specific apps, IP ranges, or user groups, potentially locking out break-glass accounts or non-interactive scenarios. Additionally, enabling security defaults disables per-user MFA, and the conditional access policies needed for nuanced control are not configurable, so its partial coverage of legacy protocols is inadequate for a strict security posture.

  • ✓

    Disable SMS and voice call authentication methods in Microsoft Entra ID.

    Why this is correct

    Disabling SMS and voice call methods removes weaker, SIM-swap-prone out-of-band mechanisms from the tenant's allowed authentication methods, reducing the risk of social engineering and phone-number hijacking. However, this action does not stop legacy authentication protocols themselves—an attacker can still replay stolen credentials via POP/IMAP if legacy clients are enabled. Disabling these methods strengthens multi-factor authentication resilience but must be combined with a Conditional Access policy that explicitly blocks legacy protocols to meet the requirement of eliminating insecure sign-in flows.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.