mediumMultiple ChoiceObjective-mapped
MS-102 Conditional Access policy Practice Question
A company uses Microsoft Entra ID P2 licenses. They want to ensure that all users are forced to use MFA when accessing a SaaS application from non-corporate networks. Corporate networks are identified by a set of IP ranges. Service accounts must be excluded from this requirement. Which policy should be created?
⚠ Common exam trap
Many exam-takers confuse Identity Protection risk policies (which are for risk-based conditional access) with location-based Conditional Access policies, or they mistakenly think per-user MFA settings can be scoped to exclude specific users or networks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policy with grant controls for MFA, targeting all users, with location condition to exclude trusted IPs, and exclude service accounts
A Conditional Access policy is the correct approach because it allows granular control over MFA enforcement based on network location and user exclusions. By targeting all users, excluding trusted IPs (corporate networks) via the location condition, and explicitly excluding service accounts, the policy ensures MFA is required only for non-corporate network access while bypassing service accounts. This aligns with the requirement to use Microsoft Entra ID P2 licenses, which include Conditional Access capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access policy with grant controls for MFA, targeting all users, with location condition to exclude trusted IPs, and exclude service accounts
Why this is correct
Correct. This configuration enforces MFA for all users from non-corporate networks while excluding trusted locations and service accounts.
- ✗
An Identity Protection user risk policy requiring MFA for medium and above risk users
Why it's wrong here
Incorrect. User risk policies are based on risk level, not network location, and would not enforce MFA from all untrusted networks.
- ✗
An Identity Protection sign-in risk policy requiring MFA for medium and above risk sign-ins
Why it's wrong here
Incorrect. Sign-in risk policies also react to risk events, not static locations, so they won't cover all sign-ins from non-corporate networks.
- ✗
Per-user MFA settings enabled for all users with trusted IPs configured in MFA service settings
Why it's wrong here
Incorrect. Per-user MFA is a legacy method that does not allow granular application targeting or easy exclusion of service accounts; Conditional Access is the recommended approach.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
About these practice questions
One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.