AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your organization has a hybrid identity environment with Microsoft Entra ID (formerly Azure AD) and on-premises Active Directory. You are using Microsoft Defender for Cloud to monitor security posture. You notice that the recommendation 'MFA should be enabled on accounts with owner permissions on your subscription' shows a status of 'Unhealthy' for some accounts, but those accounts already have Microsoft Entra Conditional Access policies requiring MFA. What is the most likely reason for the discrepancy?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Defender for Cloud evaluates the 'per-user' MFA state, which is separate from Conditional Access.
The correct answer is C: Defender for Cloud evaluates the 'per-user' MFA state, which is separate from Conditional Access. Microsoft Defender for Cloud's MFA recommendation checks whether each account has MFA enabled at the per-user level in Microsoft Entra ID (the legacy per-user MFA setting), not whether Conditional Access policies enforce MFA at sign-in. Therefore, accounts protected only by Conditional Access can still appear 'Unhealthy' because their per-user MFA status remains disabled. Option A is wrong because the scenario states the Conditional Access policies require MFA, so the discrepancy is not caused by policy scope. Option B is wrong because guest users can be protected by MFA through Conditional Access. Option D is wrong because Azure subscription IAM does not configure MFA; MFA is an identity-level control in Microsoft Entra ID.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Conditional Access policies are not applied to all users; some users bypass MFA.
Why it's wrong here
The recommendation appears not because some users bypass MFA, but because Defender for Cloud inspects the legacy per-user MFA status in Microsoft Entra ID, which remains 'disabled' for users who are routed through Conditional Access policies. Conditional Access is an external enforcement layer and does not update the per-user MFA flag. Therefore, the presence of the recommendation indicates a mismatch between the evaluation method and the actual Conditional Access configuration, not an MFA bypass.
- ✗
The accounts are guest users from another tenant; MFA cannot be enforced.
Why it's wrong here
Guest users are fully valid for MFA enforcement; their home tenants can require MFA via cross-tenant access settings, or the resource tenant can enforce MFA using Conditional Access policies. Defender for Cloud checks the per-user MFA state of the guest account in the current tenant, not the home tenant's policy, so it is entirely possible for a guest to have MFA enabled. Thus, the claim that MFA 'cannot be enforced' for guest accounts is incorrect and would not explain why the recommendation appears.
- ✓
Defender for Cloud evaluates the 'per-user' MFA state, which is separate from Conditional Access.
Why this is correct
Defender for Cloud's identity recommendations rely on the per-user MFA state in Microsoft Entra ID, which is a distinct flag set at the user level independent of any Conditional Access policies. Even when an organization has robust Conditional Access requiring MFA for all users, the per-user MFA property may still be 'Disabled', causing the recommendation to flag accounts as non-compliant. This is why the recommendation persists even when there is no actual MFA bypass, making this the correct explanation.
- ✗
The recommendation requires MFA to be configured in the subscription's access control (IAM) blade.
Why it's wrong here
MFA configuration is not an IAM blade setting; per-user MFA is managed in the Microsoft Entra ID directory, not the subscription's access control pane. The IAM blade is used for assigning RBAC roles like Owner or Contributor, not for enabling authentication methods. Defender for Cloud references those role assignments to decide which accounts to evaluate, but the MFA state itself comes from Microsoft Entra ID, so configuring MFA via IAM is irrelevant and would not resolve the recommendation.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.