Courseiva
hardMultiple Choice

MS-102 Practice Question: A company (Contoso) frequently collaborates with…

A company (Contoso) frequently collaborates with a partner company (Fabrikam) via B2B collaboration. Contoso wants to require Fabrikam's guest users to perform MFA using Contoso's MFA policies, ignoring any MFA claims from the Fabrikam home tenant. However, Fabrikam's users already have MFA enabled in their home tenant. What should Contoso configure in their cross-tenant access settings?

⚠ Common exam trap

Many exam-takers think they need to explicitly 'block MFA' (Option C) rather than understanding that disabling trust for MFA claims achieves the same effect by ignoring the external tenant's MFA, forcing Contoso's own MFA policies to apply.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable trust for MFA from the external tenant in the cross-tenant access settings

Contoso wants to ignore MFA claims from Fabrikam's home tenant and enforce its own MFA policies on Fabrikam's guest users. In cross-tenant access settings, disabling trust for MFA from the external tenant ensures that Contoso does not honor any MFA claims issued by Fabrikam, thereby requiring Fabrikam's users to perform MFA again according to Contoso's conditional access policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the inbound trust settings to accept MFA claims from Fabrikam

    Why it's wrong here

    Accepting MFA claims from Fabrikam tells Contoso to honor the MFA assertion issued by Fabrikam for guest users. Because the goal is to have Contoso's own MFA policies applied to those users, honoring Fabrikam's MFA means Fabrikam users would already be considered MFA-verified and could bypass a Contoso conditional access MFA grant. This directly contradicts the requirement, so this setting is incorrect.

  • ✗

    Set the inbound trust settings to accept compliant device claims

    Why it's wrong here

    The 'Accept compliant device claims' trust control is unrelated to multi-factor authentication; it governs whether Contoso trusts device compliance status reported by Fabrikam. Device compliance indicates that the device meets the external tenant's Intune policies, but it says nothing about the user having performed MFA. Configuring this would not force Contoso MFA and would instead potentially allow compliant devices to satisfy device-based conditional access conditions without MFA.

  • ✗

    Set the inbound trust settings to block MFA and require Contoso's MFA

    Why it's wrong here

    There is no 'block MFA' option in the cross-tenant access configuration. The trust settings are checkboxes that determine which claims Contoso will accept from Fabrikam, and the absence of a checked MFA trust means the claim is not honored, not that MFA is actively blocked. The correct configuration is simply to leave the MFA trust checkbox disabled so Contoso's MFA requirement is evaluated for guest users.

  • ✓

    Disable trust for MFA from the external tenant in the cross-tenant access settings

    Why this is correct

    Disabling trust for MFA from the external tenant prevents Contoso from honoring the MFA claim that Fabrikam issued in its own tenant. As a result, when Fabrikam guest users access Contoso resources, Entra ID treats their session as not having completed MFA and applies Contoso's conditional access policies. This ensures that Contoso's own MFA requirements, whether via conditional access or per-user MFA, are enforced for partner users.

Go deeper

Related to this question

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.