AZ-500 Secure identity and access Practice Question
Your company uses Microsoft Entra ID with a hybrid identity model. You need to implement a solution that allows you to block legacy authentication attempts while still allowing modern authentication protocols. What should you use?
⚠ Common exam trap
Many candidates confuse Identity Protection's risk-based detection with the ability to block legacy authentication, or assume that enabling MFA alone will prevent legacy auth, when in fact legacy clients can still authenticate with just a password if the protocol is not explicitly blocked.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy to block legacy authentication
Conditional Access policies in Microsoft Entra ID allow you to explicitly block legacy authentication protocols (such as POP3, IMAP, SMTP, and basic auth) while permitting modern authentication (OAuth 2.0, OpenID Connect). By targeting the 'Client apps' condition and selecting 'Exchange ActiveSync clients' and 'Other clients', you can block all legacy auth attempts without affecting modern protocol traffic. This is the precise, granular control required for a hybrid identity model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a Conditional Access policy to block legacy authentication
Why this is correct
A Conditional Access policy can be configured with the 'Client apps' condition to specifically block legacy authentication (e.g., basic auth over POP, IMAP, SMTP, or Exchange ActiveSync) while allowing modern OAuth 2.0 and OpenID Connect-based client flows. This provides granular control, so you can set exclusions for service accounts or privileged users and combine with session controls like MFA or sign-in frequency. This is the only option that selectively targets the authentication protocol itself without altering the modern authentication experience.
- ✗
Enable Security defaults
Why it's wrong here
Security defaults do block legacy authentication, but they apply as a tenant-wide baseline that also enforces MFA for every user and blocks all legacy protocols without exception. This means you cannot create granular Conditional Access policies or exclude specific users (like emergency access accounts) when security defaults are enabled. For a hybrid identity environment requiring selective modern protocol support and custom conditions, security defaults are too restrictive and cannot be fine-tuned to allow specific client applications.
- ✗
Use Identity Protection to detect legacy authentication
Why it's wrong here
Identity Protection evaluates user and sign-in risk (e.g., impossible travel or leaked credentials) and can trigger risk-based remediation such as MFA prompts or password reset, but it does not inspect or block the underlying authentication protocol. Legacy authentication requests without modern auth capabilities never trigger Conditional Access or risk policy evaluation the same way, and Identity Protection cannot block based on protocol alone. Thus it may flag suspicious legacy sign-ins but cannot prevent them from reaching the application.
- ✗
Configure MFA for all users
Why it's wrong here
Requiring MFA for all users is a critical security control, but legacy authentication protocols (such as IMAP, POP, and older SMTP) do not support the modern MFA challenge flow, so they simply ignore the MFA requirement and allow sign-in with credentials alone. MFA adds a second factor to modern authentication, but it does not block or detect the use of legacy protocols, leaving the tenant susceptible to password spraying and brute-force attacks over basic auth. This option fails to address the specific legacy authentication risk.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.