Courseiva
mediumMultiple Choice

MS-102 Practice Question: A company uses Microsoft Entra ID P2 licenses and…

A company uses Microsoft Entra ID P2 licenses and wants to enforce multi-factor authentication (MFA) for all users when accessing corporate applications. However, a small group of break-glass accounts must be excluded from MFA requirements to ensure emergency access. The administrator creates a Conditional Access policy targeting all users. Which configuration should be applied to achieve the exclusion?

⚠ Common exam trap

Many exam-takers confuse session controls (like sign-in frequency) with grant controls (like MFA requirement), or incorrectly assume that a lower-priority policy can override a higher-priority policy that includes the same users, when in fact exclusion is the only reliable method to bypass a policy targeting all users.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Under 'Assignments' > 'Users and groups', select 'Exclude' and choose the security group containing break-glass accounts.

Conditional Access policies in Microsoft Entra ID allow administrators to exclude specific users or groups from policy enforcement. By excluding the security group containing break-glass accounts under 'Assignments' > 'Users and groups', the MFA requirement is applied to all other users while ensuring emergency access accounts remain unblocked. This is the standard and recommended approach for handling break-glass accounts in a Conditional Access policy targeting all users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set 'Grant' control to 'Require multi-factor authentication' and include all users including break-glass accounts.

    Why it's wrong here

    In a Conditional Access policy, the 'Grant' control is applied to every identity in the 'Include' scope. If you add break-glass accounts to the Include list, the policy will require MFA for them, potentially locking you out during an emergency when MFA methods are unavailable or the account has no registered methods. Break-glass accounts must be explicitly excluded from the policy's Assignments, not included; simply relying on other configurations will not exempt them.

  • ✓

    Under 'Assignments' > 'Users and groups', select 'Exclude' and choose the security group containing break-glass accounts.

    Why this is correct

    This is the correct approach because the 'Exclude' setting under 'Assignments' > 'Users and groups' removes the selected security group from the policy's scope entirely. By excluding the group that contains your break-glass accounts, the Conditional Access policy will require MFA for all other users, while the excluded accounts remain accessible for emergency use. This is the recommended pattern from Microsoft, as group-based exclusions are easy to audit and manage, and they ensure break-glass accounts are never subject to the MFA grant control.

  • ✗

    Under 'Session' controls, configure 'Sign-in frequency' with a value of 0 to disable MFA for break-glass accounts.

    Why it's wrong here

    The 'Sign-in frequency' session control determines how often a user must reauthenticate during an active session, not whether MFA is required on the initial sign-in. Setting it to 0 disables the reauthentication prompt, but the MFA requirement comes from the 'Grant' control, which is separate. Also, session controls apply after authentication and cannot exclude accounts from the policy; exclusion is only handled at the Assignments level. Therefore, this option does nothing to disable MFA for break-glass accounts.

  • ✗

    Create a separate policy for break-glass accounts that does not impose MFA and assign it a lower priority.

    Why it's wrong here

    Creating a separate Conditional Access policy that does not impose MFA and assigning it a lower priority will not work because all policies that apply to a user are evaluated together, and their grant controls are combined. If the main policy includes the break-glass accounts and requires MFA, the separate policy cannot override that requirement—grant controls are additive, not mutually exclusive. Exclusion is the only reliable way to prevent a policy from applying; priority only affects which policy takes precedence for conflicting session controls, not whether a grant control is enforced.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.