hardMultiple Choice
MS-102 Practice Question: Needs to restrict access to Microsoft 365 admin…
An organization needs to restrict access to Microsoft 365 admin center to only specific users. Which approach should be used?
⚠ Common exam trap
Test-takers frequently confuse role-based access control (assigning Global Admin) with access control to the admin center itself, assuming limiting role assignments is sufficient, but Conditional Access policies are required to explicitly block or allow access to the admin portals regardless of role membership.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy targeting the Microsoft Admin Portals cloud app
A Conditional Access policy targeting the 'Microsoft Admin Portals' cloud app allows granular control over which users can access the Microsoft 365 admin center. This policy can enforce conditions such as user/group membership, device compliance, or location to restrict access, ensuring only specific authorized users can reach the admin portals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable MFA for all admins
Why it's wrong here
MFA for admins strengthens authentication, but after a successful MFA challenge the session is still granted, so it does not block or gate access to Microsoft 365 admin portals. MFA is an identity-security control, not an access-control or authorization policy; it cannot apply conditions such as device state, network location, or sign-in risk. In fact, a compromised admin session could still access portals, and non-admin users with delegated portal permissions remain entirely unaffected.
- ✓
Create a Conditional Access policy targeting the Microsoft Admin Portals cloud app
Why this is correct
A Conditional Access policy that targets the Microsoft Admin Portals cloud app is correct because it applies grant and session controls directly to the Azure portal and Microsoft 365 admin centers. You can configure conditions such as IP location, device compliance, or sign-in risk and then choose Block access, require MFA, require a hybrid Microsoft Entra ID joined device, or require a compliant device. This prevents all users—including non-admins who might normally reach certain admin pages—from accessing admin experiences outside the allowed criteria, making it the most direct and effective way to restrict admin portal access.
- ✗
Assign Global Admin role only to required users
Why it's wrong here
Limiting Global Admin role assignments only removes the most privileged role, but access to admin portals is not the same as possessing the Global Admin role. Many other Microsoft Entra ID roles—such as Exchange Administrator, SharePoint Administrator, or Billing Administrator—provide portal access, and users with delegated permissions or lower-level roles can still enter those experiences. Role assignment minimization is a least-privilege practice, not a portal access-control mechanism; it reduces the damage a compromised global admin can do but leaves other admin roles and delegated users able to access the portals.
- ✗
Use Privileged Identity Management
Why it's wrong here
Privileged Identity Management (PIM) is an identity-governance feature that provides just-in-time role activation, approval workflows, and time-bound assignments for privileged Microsoft Entra ID roles. It does not create an access-control decision at the portal entry point; once a user activates a role, they are granted the same portal access as any other member of that role. PIM also does not apply to non-privileged users or to standard users who can access certain self-service admin pages, so it cannot restrict their portal access at all.
Go deeper
Related to this question
Learn chapter
Compliance Administration
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.