Courseiva
mediumMultiple ChoiceObjective-mapped

Block Sign-Ins from High-Risk Countries Using Conditional Access Location Condition

A company uses Microsoft Entra ID with Pass-through Authentication. The security team wants to block all sign-ins from countries that are not approved (e.g., high-risk regions). Which feature should they use?

Quick Answer

The correct answer is a Conditional Access policy with the country location condition. This feature is the right choice because it evaluates the geographic origin of every sign-in request by mapping the user’s public IP address to a country, then applies a block access control to any request originating from high-risk or unapproved regions. On the MS-102 exam, this scenario tests your understanding of how Conditional Access location conditions work within Microsoft Entra ID, often appearing as a distractor against options like Named Locations in Identity Protection or a simple IP allow list. A common trap is confusing location-based blocking with Identity Protection’s risk policies—remember that location is a direct condition, not a risk signal. Memory tip: think “Geo-block, not risk-block” to keep the distinction clear.

⚠ Common exam trap

Test-takers frequently confuse Named locations (which are just definitions) with the actual enforcement mechanism, forgetting that a Conditional Access policy is required to apply the block action based on those locations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conditional Access policy with country location condition

Conditional Access policies in Microsoft Entra ID can include a location condition that uses IP addresses to determine the country of origin. By configuring a policy to block access from specific countries (e.g., high-risk regions), the security team can enforce this requirement. This is the correct feature because it directly evaluates the geographic location of the sign-in request and applies an access control (block) accordingly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conditional Access policy with country location condition

    Why this is correct

    Correct. Conditional Access allows blocking or allowing access based on country using Named Locations.

  • Identity Protection sign-in risk policy

    Why it's wrong here

    Incorrect. Sign-in risk policies react to risk events, not geographic locations.

  • Identity Protection user risk policy

    Why it's wrong here

    Incorrect. User risk policies are based on user risk level, not location.

  • Named locations with blocked countries

    Why it's wrong here

    Incorrect. Named locations are a configuration block, not a policy by themselves; they must be used in a Conditional Access policy to enforce blocking.

About these practice questions

Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MS-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Contoso wants to require multi-factor authentication (MFA) for all users when accessing cloud applications from any network except the corporate headquarters (trusted IP range). They plan to use Azure AD Conditional Access. Which two components must be configured to achieve this requirement? (Select all that apply.)

medium
  • A.Conditional Access policy targeting all users and cloud apps, with conditions for locations
  • B.named location defining the corporate headquarters' trusted IP ranges
  • C.An Identity Protection user risk policy
  • D.An MFA registration policy requiring users to register for MFA

Why A: A Conditional Access policy must be created to enforce MFA based on location conditions. The policy targets all users and cloud apps, and uses the 'locations' condition to exclude the trusted IP range (corporate headquarters) while requiring MFA for all other locations. This ensures MFA is triggered only when access originates from outside the trusted network.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.