AZ-500 Secure identity and access Practice Question
Your organization wants to ensure that users accessing Office 365 from outside the corporate network must use MFA. What is the most efficient way to enforce this?
⚠ Common exam trap
Many candidates choose a broad policy (Option B) thinking it covers all scenarios, but the question specifically asks for Office 365, so the most efficient solution targets only that app to avoid unnecessary MFA prompts on other cloud services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy for Office 365 with location condition and require MFA.
It specifically targets Office 365 cloud apps and uses the location condition to restrict MFA enforcement to access from outside the corporate network. This is the most efficient approach as it applies only to the relevant application and network location, minimizing user friction while meeting the requirement exactly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable MFA for all users in Microsoft Entra ID.
Why it's wrong here
Enabling tenant-wide MFA through Microsoft Entra ID's per-user MFA register forces a second factor on every sign-in event, including internal corporate network sign-ins and service-side automated logons. It does not evaluate the user's geographic network origin, so it cannot differentiate between a user at headquarters and a user logging in from an untrusted external network. This removes the external-access-only constraint the organization needs and creates avoidable authentication friction for all users.
- ✗
Create a Conditional Access policy for all cloud apps with location condition.
Why it's wrong here
A Conditional Access policy targeting 'All cloud apps' with a location condition evaluates every application registered in Microsoft Entra ID, not only Office 365. That means external users would be forced through MFA for Azure Resource Manager, Dynamics 365, Power Platform, and any other integrated enterprise app, which is overbroad. It fails the narrower requirement to enforce MFA solely for users accessing Office 365, and it also lacks the granular per-app exclusions that an Office 365-targeted policy can provide.
- ✗
Use Conditional Access with device compliance condition.
Why it's wrong here
A device compliance condition in Conditional Access verifies device health characteristics such as Intune compliance status, BitLocker encryption, or OS patch level, but it is orthogonal to network location. A compliant personal device can still be used from an untrusted external café, while an uncompliant device might be blocked even when connecting from the corporate network. Moreover, device compliance does not itself enforce MFA as a grant control; it gates access on device state. Thus this approach does not satisfy the requirement of requiring MFA for external access to Office 365.
- ✓
Create a Conditional Access policy for Office 365 with location condition and require MFA.
Why this is correct
Create a Conditional Access policy that targets the Office 365 cloud app, sets the location condition to include an untrusted named location or exclude trusted corporate IP ranges, and grants access only when MFA is satisfied. Because the scope is limited to the Office 365 application and an external location condition, internal users on the corporate trusted network are not subjected to MFA prompts, while external accesses to Exchange Online, SharePoint Online, and Teams are challenged. This is the least-privilege approach that precisely matches the stated requirement.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.