Courseiva
mediumMultiple ChoiceObjective-mapped

MS-102 Conditional Access policy Practice Question

A company uses Microsoft Entra ID P2 licenses. They want to ensure that all users are forced to use MFA when accessing a SaaS application from non-corporate networks. Corporate networks are identified by a set of IP ranges. Service accounts must be excluded from this requirement. Which policy should be created?

⚠ Common exam trap

Many exam-takers confuse Identity Protection risk policies (which are for risk-based conditional access) with location-based Conditional Access policies, or they mistakenly think per-user MFA settings can be scoped to exclude specific users or networks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conditional Access policy with grant controls for MFA, targeting all users, with location condition to exclude trusted IPs, and exclude service accounts

A Conditional Access policy is the correct approach because it allows granular control over MFA enforcement based on network location and user exclusions. By targeting all users, excluding trusted IPs (corporate networks) via the location condition, and explicitly excluding service accounts, the policy ensures MFA is required only for non-corporate network access while bypassing service accounts. This aligns with the requirement to use Microsoft Entra ID P2 licenses, which include Conditional Access capabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conditional Access policy with grant controls for MFA, targeting all users, with location condition to exclude trusted IPs, and exclude service accounts

    Why this is correct

    Correct. This configuration enforces MFA for all users from non-corporate networks while excluding trusted locations and service accounts.

  • An Identity Protection user risk policy requiring MFA for medium and above risk users

    Why it's wrong here

    Incorrect. User risk policies are based on risk level, not network location, and would not enforce MFA from all untrusted networks.

  • An Identity Protection sign-in risk policy requiring MFA for medium and above risk sign-ins

    Why it's wrong here

    Incorrect. Sign-in risk policies also react to risk events, not static locations, so they won't cover all sign-ins from non-corporate networks.

  • Per-user MFA settings enabled for all users with trusted IPs configured in MFA service settings

    Why it's wrong here

    Incorrect. Per-user MFA is a legacy method that does not allow granular application targeting or easy exclusion of service accounts; Conditional Access is the recommended approach.

About these practice questions

One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.