mediumMultiple Choice
MS-102 Practice Question: With Microsoft Entra ID P2 licenses wants to…
An organization with Microsoft Entra ID P2 licenses wants to require multi-factor authentication (MFA) for all users but allow them to register their authentication methods before being forced to use MFA. Which configuration should they implement?
⚠ Common exam trap
MS-102 often tests the difference between Security Defaults, per-user MFA, and Conditional Access — candidates pick Security Defaults because it 'requires MFA', but it lacks the registration campaign and granular control the scenario demands.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policy with MFA grant and a registration campaign
A Conditional Access policy with an MFA grant control enforces MFA for all users, and a registration campaign (or the combined registration experience) allows users to register their authentication methods before enforcement kicks in. This satisfies both the requirement to require MFA and the requirement to let users register first. Entra ID P2 licensing supports Conditional Access and the registration campaign feature.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access policy with MFA grant and a registration campaign
Why this is correct
Conditional Access with the MFA grant and an authentication registration campaign is correct because the registration campaign prompts users to enroll their MFA methods before the MFA requirement is actually enforced. This phased approach lets administrators schedule a grace period, target specific groups, and ensure users have security info registered, so the MFA challenge is not a blocking first-time event. Thus, it directly matches the scenario's need for pre-registration.
- ✗
Security defaults
Why it's wrong here
Security defaults enforce MFA for all users at their very next interactive sign-in, without any staged or separate registration campaign. These defaults are an all-or-nothing baseline designed for tenants not enforcing broader Conditional Access policies, so you cannot delay enforcement with a grace period or target specific users or groups. Consequently, while security defaults require MFA, they do not satisfy the requirement to let users pre-register before MFA is enforced.
- ✗
Per-user MFA
Why it's wrong here
Per-user MFA, toggled from the legacy MFA blade, immediately changes a user's state to 'Enforced' and forces them to register at the first MFA challenge. It offers no customizable registration campaign, no scheduling, and no group-level targeting, so the first prompt for registration occurs simultaneously with the MFA requirement. This means users are not given any opportunity to enroll before the requirement takes effect, failing the pre-registration scenario.
- ✗
Identity Protection user risk policy
Why it's wrong here
Identity Protection's user risk policy only requires MFA when a user's risk level is elevated, based on signals like leaked credentials or impossible travel, so it does not apply to every user. Even for those risky users, the policy enforces MFA as a risk-based response and does not include a registration campaign to pre-enroll methods. Therefore, it is far too narrow and lacks the enrollment sequencing needed for universal pre-registration.
Go deeper
Related to this question
Learn chapter
Intune and Conditional Access Integration
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.