You are the Microsoft 365 administrator for Fabrikam, which has a Microsoft 365 E5 tenant and Microsoft Entra ID P2. The security team wants to require multifactor authentication for all users when they access any cloud app from outside the corporate network, but they do not want to affect users working in the office. You create a Conditional Access policy named CA01. You need to configure the policy to meet the requirements. What should you do?
Excluding the corporate network location from the Locations condition ensures the policy applies only to sign-ins from outside the trusted network. Setting Grant to Require multifactor authentication enforces MFA for those sign-ins, and enabling the policy makes it active. This precisely matches the requirement to prompt external users while leaving office users unaffected.
Why this answer
The requirement is to enforce MFA only for sign-ins originating outside the corporate network. A Conditional Access policy must include All users and All cloud apps as the assignment scope, then use the Locations condition to exclude the trusted corporate network. With the Grant control set to Require multifactor authentication and the policy enabled, external sign-ins are challenged while internal sign-ins remain unaffected.
Exam trap
The trap here is assuming that selecting Any location automatically limits the policy to external networks, when in fact Any location includes trusted locations unless you explicitly exclude them.