Courseiva
easyMultiple Choice

MD-102 A company uses Microsoft 365 E3 licenses Practice Question

A company uses Microsoft 365 E3 licenses. They need to enforce that all users must use the Microsoft Authenticator app for MFA instead of SMS or phone call. What should the administrator configure?

⚠ Common exam trap

Many candidates confuse the Authentication methods policy with Conditional Access policies, assuming that a Conditional Access policy can restrict MFA methods, but in reality, Conditional Access only controls when MFA is required, not which methods are allowed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authentication methods policy

The Authentication methods policy (B) is the correct configuration because it allows administrators to control exactly which authentication methods users can register and use for MFA. By targeting the policy to all users and disabling SMS and voice call while enabling Microsoft Authenticator (push notifications or OTP), the requirement is met. This policy supersedes legacy MFA settings and provides granular control over modern authentication methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MFA service settings in the legacy portal

    Why it's wrong here

    Legacy MFA service settings only toggle verification methods globally; they cannot restrict users to the Microsoft Authenticator app alone. It is tempting as the historical MFA configuration surface, but enforcing a single method requires an Authentication Methods policy in Microsoft Entra ID with the Authenticator method enabled and SMS and voice disabled.

  • ✓

    Authentication methods policy

    Why this is correct

    The authentication methods policy in Microsoft Entra ID lets you enable Microsoft Authenticator while disabling SMS and voice call for all users, directly satisfying the requirement to enforce app-based MFA. Unlike legacy per-user MFA settings, it provides granular control over which methods are available tenant-wide.

  • ✗

    Security defaults

    Why it's wrong here

    Security defaults enable MFA for all users but permit any registered method, including SMS and phone call, so they cannot restrict authentication to the Authenticator app. They suit tenants without Conditional Access licensing needing baseline protection, not method-specific enforcement.

  • ✗

    Conditional Access policy

    Why it's wrong here

    Conditional Access grants access but does not mandate a specific MFA method; authentication method policies under Microsoft Entra ID control which methods users may register and use. Conditional Access is tempting because it enforces MFA, yet it cannot restrict users to the Authenticator app over SMS or voice call.

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.