Courseiva
mediumMultiple Choice

MS-102 Uses Microsoft Entra ID P2 licenses Practice Question

An organization uses Microsoft Entra ID P2 licenses. They want to implement a policy that forces users to perform multi-factor authentication (MFA) only when they sign in from an untrusted location. The trusted locations include the corporate office IP range. Which type of policy should they create?

⚠ Common exam trap

Many candidates confuse the purpose of Identity Protection policies (risk-based) with Conditional Access policies (condition-based), leading candidates to select A when the question explicitly requires location-based enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access policy

Conditional Access policies in Microsoft Entra ID allow administrators to enforce MFA based on conditions like location. By configuring a policy that targets all users and cloud apps, with a condition excluding trusted IP ranges (corporate office), MFA is only triggered when sign-ins originate from untrusted locations. This is the precise mechanism for location-based MFA enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Identity Protection user risk policy

    Why it's wrong here

    Identity Protection user risk policies evaluate the likelihood that a user account has been compromised based on risk signals such as leaked credentials or impossible travel. The policy triggers remediation actions like requiring MFA or a password change only when the user's risk level reaches a configured threshold. It does not inspect the sign-in request's location, so it cannot enforce MFA solely for untrusted network addresses or geographical areas.

  • ✓

    Conditional Access policy

    Why this is correct

    A Conditional Access policy is the correct tool because it can include a location condition that references named locations or trusted/untrusted IP ranges. When a user attempts to sign in from a location that is not trusted, the policy's grant control can require MFA as an additional verification step. This matches the requirement to prompt for MFA only from untrusted locations, without affecting trusted network sign-ins.

  • ✗

    MFA registration policy

    Why it's wrong here

    The MFA registration policy instructs users to enroll in Microsoft Entra ID MFA by a set deadline, but it does not evaluate sign-in context such as source IP or geolocation. It only tracks registration status and can remind or block users until they complete enrollment. Therefore it cannot selectively require MFA based on whether the location is trusted or untrusted.

  • ✗

    Authentication methods policy

    Why it's wrong here

    The authentication methods policy controls which MFA methods users may use—such as app code, phone call, or FIDO2—and sometimes enforces method defaults for specific groups. It does not contain a location condition and never prompts for authentication based on network address or geographic trust. Its purpose is to define available credentials, not to make runtime access decisions based on where the sign-in originates.

Go deeper

Related to this question

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.