AZ-500 Secure identity and access Practice Question
Your company uses Microsoft Entra ID. You need to block sign-ins from countries where your company does not operate. Which approach should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy to block access from those countries
The correct option is B: create a Conditional Access policy to block access from those countries. Conditional Access is the Microsoft Entra ID feature designed to enforce sign-in decisions based on conditions such as location, and a policy can be scoped to all users and cloud apps with a Block grant control, using a Named location that defines the countries to exclude or block. Option D is only a building block—Named locations merely define geographic IP ranges and do not by themselves block anything. Option A (MFA for all users) adds an authentication requirement but does not prevent sign-ins from specific countries, and Option C (Identity Protection user risk policy) responds to risky user behavior, not geographic origin.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure MFA for all users
Why it's wrong here
Requiring MFA for all users strengthens authentication but does not evaluate the sign-in's source location. MFA only proves possession of a second factor after a user presents valid credentials; it has no concept of country or IP address and therefore cannot prevent users in unauthorized countries from completing authentication. To block by geography, a Conditional Access condition based on Named Locations is needed, not an authentication-strength policy.
- ✓
Create a Conditional Access policy to block access from those countries
Why this is correct
Create a Conditional Access policy that targets the 'Locations' condition and specifies the relevant countries as Named Locations. When you set the access control to 'Block access', Entra ID checks the sign-in IP address at runtime and denies authentication if it maps to a blocked country. This policy must be assigned to the appropriate users and apps, and should exclude emergency access accounts to avoid tenant lockout.
- ✗
Use Identity Protection user risk policy
Why it's wrong here
Identity Protection user risk policies use machine learning to assess the probability that a user or sign-in is compromised, such as impossible travel or leaked credentials, but they do not implement a deterministic geographic block. A foreign sign-in might increase sign-in risk and trigger a risk-based control, but the policy only reacts to a calculated risk score, not a configured country list. Blocking all sign-ins from specific countries requires a Conditional Access policy with explicitly configured Named Locations.
- ✗
Add those countries as Named locations
Why it's wrong here
Adding those countries as Named locations is a necessary step, but by itself it does not block sign-ins. You must also create a Conditional Access policy that uses those Named locations in a block condition.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.