Courseiva
mediumMultiple Choice

MS-102 Practice Question: A company uses Microsoft Entra Conditional Access

A company uses Microsoft Entra Conditional Access. The security team wants to require multi-factor authentication (MFA) for all users when accessing the Azure portal, except when they are connecting from the corporate network (which is defined as a trusted location). How should the Conditional Access policy be configured?

⚠ Common exam trap

The trap here is that candidates often select 'All cloud apps' (Option B) thinking it covers the Azure portal, but this over-scopes the policy and forces MFA on all applications, which is not the requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Conditional Access policy with all users, cloud apps = Microsoft Azure Management, Conditions > Locations = all locations, exclude the corporate network, Grant = Require multi-factor authentication.

It targets only the Azure Portal (Microsoft Azure Management cloud app), applies MFA to all locations except the trusted corporate network, and excludes the corporate network from the policy. This ensures MFA is required for all access attempts from untrusted locations while allowing direct access from the corporate network without MFA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a Conditional Access policy with all users, cloud apps = Microsoft Azure Management, Conditions > Locations = all locations, exclude the corporate network, Grant = Require multi-factor authentication.

    Why this is correct

    This policy correctly targets only the Microsoft Azure Management cloud app, which covers the Azure portal, Azure CLI, and PowerShell. By selecting all locations but excluding the corporate network, any sign-in from an untrusted location—such as home, hotel, or airport—will be challenged for MFA. Granting 'Require multi-factor authentication' fulfills the requirement to protect admin access while preserving smooth access from the trusted corporate network.

  • ✗

    Create a Conditional Access policy with all users, cloud apps = All cloud apps, Conditions > Locations = all locations, exclude the corporate network, Grant = Require multi-factor authentication.

    Why it's wrong here

    Applying 'All cloud apps' broadens the scope far beyond Azure Management, so every SaaS app and resource in your tenant—for example Exchange Online, SharePoint, or custom LOB apps—would trigger MFA from outside the corporate network. This not only creates excessive authentication friction for everyday productivity apps but also may break legacy protocols or non-interactive workloads that cannot handle MFA prompts. The requirement is specific to Azure Management, so this over-broad control is incorrect even though it does enforce MFA from non-corporate locations.

  • ✗

    Create a Conditional Access policy with all users, cloud apps = Microsoft Azure Management, Conditions > Locations = Corporate network, Grant = Block.

    Why it's wrong here

    This policy is doubly wrong: the condition is limited to the corporate network, so external users will not be blocked at all. Moreover, an explicit block grant on the corporate network would prevent administrators from signing into the Azure portal even from the trusted office, which is the opposite of the intended security control. A block grant when their location matches corporate network has no effect outside that location, leaving the actual risk surface unaddressed.

  • ✗

    Create a Conditional Access policy with all users, cloud apps = Microsoft Azure Management, Conditions > Locations = Corporate network, Grant = Require multi-factor authentication.

    Why it's wrong here

    This policy requires MFA only when the sign-in originates from the corporate network, leaving external sign-ins—the high-risk scenarios—completely unprotected. Conditional Access evaluates the 'Locations' condition as an include, so a user accessing Azure Management from outside the corporate network would not match the policy and would not be prompted. MFA should be enforced for untrusted networks, while corporate network should be exempted as a trusted location; this option inverts the intended trust boundary.

Go deeper

Related to this question

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.