Courseiva
mediumMultiple ChoiceObjective-mapped

MS-102 A company uses Microsoft Entra ID P2 licenses Practice Question

A company uses Microsoft Entra ID P2 licenses. They want to block all authentication attempts from an internal app that uses legacy authentication protocols (POP3, IMAP, SMTP) because these protocols cannot enforce multi-factor authentication. Which Conditional Access policy setting should be used?

⚠ Common exam trap

Candidates often confuse 'Require MFA' (which still allows legacy apps to attempt authentication and fail silently) with 'Block legacy authentication' (which explicitly prevents the authentication attempt at the protocol level), leading them to choose Option A instead of B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Block access for apps using legacy authentication

The scenario explicitly requires blocking authentication attempts from an internal app using legacy protocols (POP3, IMAP, SMTP) that cannot enforce multi-factor authentication. The 'Block access for apps using legacy authentication' Conditional Access setting targets client apps that use legacy authentication protocols, effectively preventing any authentication from those apps regardless of user or device compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Grant access requiring multi-factor authentication

    Why it's wrong here

    Requiring MFA as an access condition does not explicitly identify or disable legacy authentication protocols. Because legacy clients such as Exchange Online PowerShell or Outlook basic auth cannot perform interactive modern authentication challenges, they would be denied access indirectly—but this grant control applies across all protocols and does not provide the granular 'Client apps' condition that directly blocks legacy auth traffic. The correct approach is to use the Client apps condition to block 'Other clients' and 'Exchange ActiveSync clients'.

  • Block access for apps using legacy authentication

    Why this is correct

    In a Conditional Access policy, the 'Client apps' condition includes 'Exchange ActiveSync clients' and 'Other clients'. Selecting these options explicitly targets protocols such as POP3, IMAP4, SMTP, and Exchange Web Services that rely on basic authentication instead of modern authentication. This blocks legacy authentication traffic while still allowing modern, MFA-capable clients, and it is the recommended way to enforce Microsoft's 'block legacy authentication' policy.

  • Require compliant device

    Why it's wrong here

    This grant control requires the client device to be marked as compliant by Intune (or another MDM), which typically requires the device to be enrolled and to have a compliance policy applied. However, many legacy authentication clients run on devices that are not enrolled or cannot report compliance state through basic auth; moreover, the control does not specifically target protocols—it evaluates the device state. Therefore it is unrelated to the protocol-level identification of legacy authentication and could block compliant modern clients while not explicitly preventing a legacy client on a noncompliant device from attempting basic auth (though the conditional grant would deny it).

  • Require approved client app

    Why it's wrong here

    This grant control restricts access to apps that have been marked as approved by Microsoft, such as the latest Outlook mobile app. Legacy authentication protocols like POP/IMAP/Exchange ActiveSync are not recognized as approved client apps in Conditional Access, so they do not qualify under this control. However, the condition is intended to enforce app-based access for mobile or modern clients, not to create a protocol block; it also requires the app to support the Intune SDK or have app-based CA policies. Thus it is not a replacement for directly blocking legacy authentication via the Client apps condition.

About these practice questions

This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.