hardMultiple ChoiceObjective-mapped
MS-102 Practice Question: A company invites external partners as B2B guest…
A company invites external partners as B2B guest users in Microsoft Entra ID. The partners' home tenants do not support MFA. The company wants to require MFA when guests access an internal application. What should the company configure?
⚠ Common exam trap
Test-takers frequently assume MFA must be handled by the home tenant (Option B) or that legacy Per-User MFA (Option C) works for guests, but Microsoft Entra ID requires Conditional Access policies and resource-tenant MFA registration for guest users when the home tenant cannot provide MFA claims.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a Conditional Access policy that targets all guest users, require MFA, and enable MFA registration for guests in the resource tenant.
When guest users' home tenants do not support MFA, the resource tenant must enforce MFA directly. A Conditional Access policy targeting all guest users with 'Require MFA' grant control, combined with enabling MFA registration for guests in the resource tenant, allows guests to register and use MFA methods (e.g., Microsoft Authenticator) within the resource tenant. This ensures MFA is enforced regardless of the home tenant's capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a Conditional Access policy that targets all guest users, require MFA, and enable MFA registration for guests in the resource tenant.
Why this is correct
A Conditional Access policy in the resource tenant can explicitly target guest users and apply the resource tenant's MFA requirements, independent of the home tenant's capabilities. Because the home tenants do not support MFA, the resource tenant must provide its own registration for guest users, which is enabled through MFA registration settings in the tenant. This ensures each guest can authenticate with methods governed by the resource tenant, fully satisfying the security requirement.
- ✗
Ask the partners to configure MFA in their home tenant, then trust their MFA claims.
Why it's wrong here
This approach fails for two reasons: the partners' home tenants lack MFA capability, so they cannot generate MFA claims to trust, and cross-tenant access settings only trust claims that the home tenant actually produces. Even if the home tenant could enforce MFA, this delegates critical authentication assurance to an external entity, giving the resource tenant no direct control or visibility. Since the scenario requires MFA enforcement for these guests, relying on a non-existent or external MFA claim is neither feasible nor secure.
- ✗
Use a Per-User MFA policy for guest users, but guests cannot register for MFA in the resource tenant.
Why it's wrong here
Per-User MFA is a legacy mode that operates on a user's enforced state rather than policy conditions, and it is not the recommended mechanism for securing guest access in Microsoft Entra ID. The second part of this option is also false: guest users can absolutely register for MFA in the resource tenant, either through the combined security information registration or when prompted by a Conditional Access policy that requires MFA. Therefore, this option mischaracterizes both the tooling and the registration capability.
- ✗
Create a Conditional Access policy requiring MFA for all external users, but exclude guests from known networks.
Why it's wrong here
Excluding guests from known networks would carve out a large, unnecessary exception because trusted IPs defined by the resource tenant's network policy may include locations that are not actually secure for third-party access. Since the policy requires MFA for all external users, granting a known-network exemption allows any guest connecting from those IPs to bypass MFA altogether, directly violating the stated requirement. Conditional Access exclusions should be used sparingly, and for this compliance-driven scenario the exception is clearly inappropriate.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.