mediumMultiple ChoiceObjective-mapped
MS-102 A company uses Microsoft Entra ID P1 licenses Practice Question
A company uses Microsoft Entra ID P1 licenses. They want to enforce multi-factor authentication (MFA) for all users when accessing any cloud application from networks that are not trusted corporate locations. A group named 'Emergency' must be excluded from MFA requirements. Which Conditional Access policy configuration should the administrator use?
⚠ Common exam trap
Many exam-takers confuse the location condition logic, mistakenly selecting 'trusted networks only' (Option D) thinking it applies MFA to trusted networks, when in fact it applies the policy only when the user is on a trusted network, which is the opposite of the requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign the policy to all users, exclude the Emergency group, include all cloud apps, grant MFA, and set location condition to any network or location except trusted networks.
The requirement is to enforce MFA for all users from untrusted networks, while excluding the Emergency group. The Conditional Access policy must be assigned to all users, exclude the Emergency group, include all cloud apps, require MFA as a grant control, and use a location condition set to 'any network or location except trusted networks' to target only untrusted locations. This configuration ensures MFA is triggered only when access originates from networks not defined as trusted corporate locations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign the policy to all users, exclude the Emergency group, include all cloud apps, grant access (not MFA), and set location condition to trusted networks only.
Why it's wrong here
Setting the location condition to trusted networks only and granting access (not MFA) creates a policy that exclusively applies to corporate network traffic, where users are allowed in without any additional authentication. Because the policy has no effect on untrusted networks, users connecting from outside the office will never be prompted for MFA, completely missing the requirement to secure those remote connections.
- ✗
Assign the policy to all users, exclude the Emergency group, include all cloud apps, grant MFA, and set location condition to any network or location.
Why it's wrong here
This configuration requires MFA for every authentication attempt regardless of the user's physical location, including when they are inside the corporate trusted network. That is more restrictive than needed and would cause unnecessary friction for on-premises users; the requirement specifically asks for MFA only from untrusted networks, so this policy should instead use a location condition that excludes trusted networks.
- ✓
Assign the policy to all users, exclude the Emergency group, include all cloud apps, grant MFA, and set location condition to any network or location except trusted networks.
Why this is correct
By targeting all users except the Emergency group, applying to all cloud apps, requiring MFA as a grant control, and using the location condition 'any network or location except trusted networks', this policy ensures MFA is enforced exactly when a user accesses resources from an untrusted location. Users on trusted corporate networks are exempt from MFA, while remote or external connections are challenged, and the emergency group remains available to bypass MFA in break-glass scenarios.
- ✗
Assign the policy to all users, exclude the Emergency group, include all cloud apps, grant MFA, and set location condition to trusted networks only.
Why it's wrong here
Setting the location condition to trusted networks only while requiring MFA means the policy will only evaluate and require MFA when the user is actually on the corporate network. Users outside the trusted network will not have this policy applied, so they could access cloud apps without MFA, which is the exact opposite of the security requirement.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.