How to Block Access from Countries Using Conditional Access Named Locations
Your organization uses Microsoft Entra Conditional Access. You need to block access from countries where your company does not operate. The list of blocked countries changes frequently. What is the most efficient way to manage this?
Quick Answer
The answer is to create Named Locations for blocked countries and use them in a Conditional Access policy. This is the most efficient method because Named Locations allow you to define country boundaries by IP ranges, and you can update the list of blocked countries directly within the Named Locations configuration without ever touching the Conditional Access policy itself—a critical advantage when the list changes frequently. On the MS-102 exam, this scenario tests your understanding of how to decouple policy logic from dynamic data; a common trap is to create a separate policy for each country, which is inefficient and hard to maintain. Instead, remember that Named Locations act as a centralized, reusable filter. Memory tip: think of Named Locations as a “dynamic blocklist” that you edit in one place, while the Conditional Access policy simply points to it—update the list, not the rule.
⚠ Common exam trap
Many candidates think using IP ranges directly in the policy (Option C) is more precise, but they overlook the administrative overhead of maintaining those ranges manually, whereas Named Locations with country selection provide a simpler and more scalable solution for frequently changing country lists.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create Named Locations for blocked countries and use them in Conditional Access
Named Locations in Microsoft Entra Conditional Access allow you to define countries by IP ranges and then use those locations in a policy to block access. This is the most efficient approach because you can update the list of blocked countries in the Named Locations configuration without modifying the Conditional Access policy itself, which is ideal when the list changes frequently.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Microsoft Entra multifactor authentication for all users from blocked countries
Why it's wrong here
Multifactor authentication challenges users but does not block access from a country; a user with valid credentials and a registered method still signs in. It is tempting as a strong access control, yet Conditional Access named locations with country conditions are what actually deny sign-ins by geography.
- ✗
Create a Conditional Access policy that blocks all locations except the allowed countries
Why it's wrong here
An allow-list policy blocks everything outside permitted countries, which also blocks legitimate travelling staff and partners, and still needs named locations maintained. It is tempting as a default-deny posture, but the requirement is blocking specific countries, which named-location country conditions handle directly.
- ✗
Use IP ranges in Conditional Access to block specific country IPs
Why it's wrong here
Maintaining IP ranges manually fails because country address blocks change constantly, so the list drifts out of date and requires ongoing upkeep. It is tempting for granular control, yet Conditional Access named locations with country-based conditions are the mechanism designed for frequently changing geographic blocking.
- ✓
Create Named Locations for blocked countries and use them in Conditional Access
Why this is correct
Named Locations let you define country-based restrictions once and reference them across Conditional Access policies, so frequent updates to the blocked-country list require editing only the location definition rather than every policy. This directly satisfies the stem's changing-list constraint, avoiding repeated policy reconfiguration as countries are added or removed.
Go deeper
Related to this question
Learn chapter
Entra Connect Sync Rules and Filtering
Key term
Conditional Access policy
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MS-102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization needs to implement a Conditional Access policy that blocks access from countries where the company has no business operations. Which TWO conditions should you configure?
medium- A.Device platforms
- ✓ B.Locations
- C.User risk
- ✓ D.Client apps
- E.Sign-in risk
Why B: Option B (Locations) is correct because Conditional Access uses the Locations condition to define named locations, including country/region-based IP ranges, so you can block or allow access based on the geographic origin of the sign-in. Option D (Client apps) is correct because the Client apps condition lets you scope the policy to specific client types (browser, mobile apps and desktop clients, Exchange ActiveSync, and other clients), which is required to fully enforce the geographic block across the access paths users employ. Options A (Device platforms), C (User risk), and E (Sign-in risk) do not belong because they control policy based on device OS, compromised-user likelihood, or sign-in risk level respectively, none of which restrict access by country.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.