Courseiva
easyMultiple Choice

MS-102 Practice Question: Ensure that only users from specific IP ranges…

A company needs to ensure that only users from specific IP ranges can access Exchange Online. Which tool should be used?

⚠ Common exam trap

Many candidates confuse the Security & Compliance Center's transport rules or mailbox policies with network-level access control, or they assume MFA alone can restrict access by IP, when in fact Conditional Access is the dedicated feature for location-based policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra Conditional Access with Named Locations

Microsoft Entra Conditional Access with Named Locations is the correct tool because it allows administrators to define trusted IP ranges as named locations and then enforce access policies that restrict Exchange Online access to only those IP ranges. This integrates directly with Microsoft Entra ID authentication, evaluating the user's IP address during sign-in to grant or block access based on the policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Entra Conditional Access with Named Locations

    Why this is correct

    Microsoft Entra Conditional Access with Named Locations is the correct approach because Named Locations define a set of trusted public IP address ranges or countries that can be referenced in a Conditional Access policy. You can create a policy that targets all users and either blocks sign-ins from any IP not included in the trusted location or requires additional controls such as MFA for exceptions. This provides dynamic, IP-based network access enforcement at the authentication layer.

  • ✗

    Security & Compliance Center

    Why it's wrong here

    The Security & Compliance Center is designed for governance workflows like data retention, DLP, eDiscovery, and audit logging, not for controlling who can sign in based on their network address. It does not contain any mechanism to evaluate a user's originating IP or make allow/deny decisions during authentication. Relying on it here would be a category error: it protects sensitive content, not the sign-in boundary.

  • ✗

    Multi-factor authentication

    Why it's wrong here

    Multi-factor authentication adds a second verification step, such as a code or push approval, but it never inspects the client's IP address. While users can see MFA prompts because a Conditional Access policy flagged an unfamiliar location, MFA itself is an identity-verification control, not a network-boundary control. It might raise the bar for attackers even from unauthorized IPs, but it fails to satisfy the requirement to restrict access to specific ranges.

  • ✗

    Microsoft Entra Connect

    Why it's wrong here

    Microsoft Entra Connect is a synchronization service that mirrors on-premises Active Directory objects into Microsoft Entra ID and optionally enables pass-through authentication or federation settings. It has no role in real-time authorization decisions and cannot block users based on their source IP address. Its purpose is to establish a hybrid identity baseline, not to enforce network-level access rules.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.