mediumMultiple ChoiceObjective-mapped
MD-102 A company uses Microsoft Entra ID P1 licenses Practice Question
A company uses Microsoft Entra ID P1 licenses. They want to enforce multi-factor authentication (MFA) for all users accessing the company's SaaS applications. However, they need to exclude a group of service accounts that use legacy authentication protocols. What is the recommended approach?
⚠ Common exam trap
Watch out — candidates often confuse Security defaults or per-user MFA as viable alternatives, not realizing that only Conditional Access provides the group-based exclusion and granular control required for service accounts using legacy authentication protocols.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy targeting all cloud apps, requiring MFA, and excluding the service accounts group.
Conditional Access is the recommended method for granular MFA enforcement in Microsoft Entra ID P1. It allows you to target all cloud apps (including SaaS applications) with a 'Require MFA' grant control and exclude a specific group of service accounts. This approach supports legacy authentication protocols by excluding those accounts, while Security defaults or per-user MFA would either block legacy auth or lack the necessary exclusion granularity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Security defaults and add the service accounts group to the excluded users list.
Why it's wrong here
Security defaults do not allow exclusion of specific groups; they apply to all users.
- ✗
Assign the 'Require MFA' baseline policy and exclude the service accounts group.
Why it's wrong here
Baseline policies are deprecated and do not support group exclusions.
- ✓
Create a Conditional Access policy targeting all cloud apps, requiring MFA, and excluding the service accounts group.
Why this is correct
Conditional Access allows scoping to all cloud apps and excluding specific groups.
- ✗
Enable per-user MFA and exclude the service accounts group.
Why it's wrong here
Per-user MFA does not support exclusion of groups; it's a user-level setting.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
One of 942 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.