Courseiva

How to Interpret a Conditional Access Policy JSON in Microsoft Entra ID

Which TWO permissions are required for a custom role to manage Conditional Access policies in Microsoft Entra ID?

⚠ Common exam trap

It's easy for candidates to assume 'create' or 'delete' permissions are needed for management, but Microsoft defines 'manage' as the combination of read and update, not full CRUD access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

microsoft.directory/conditionalAccessPolicies/read

To manage Conditional Access policies in Microsoft Entra ID, a custom role requires both the read and update permissions. The 'read' permission (option B) is necessary to view existing policies, while the 'update' permission (option D) is required to modify or configure policy settings. Without both, the role cannot effectively manage policies, as management implies the ability to change them.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    microsoft.directory/conditionalAccessPolicies/allProperties/read

    Why it's wrong here

    The allProperties/read permission grants access to every property of Conditional Access policies, including detailed internal fields, which is more than necessary. To manage policies, the base read and update permissions are sufficient; the broader read is not required. Granting this over-provisioned permission violates least privilege and is therefore an incorrect answer for this question.

  • ✓

    microsoft.directory/conditionalAccessPolicies/read

    Why this is correct

    The read permission is the foundational access required to view Conditional Access policies and their current configuration. Without it, an administrator cannot even see the policies that need management, making it an indispensable part of the minimal permission set. Together with update, it covers the two core operations needed for policy management: seeing the policy and changing it.

  • ✗

    microsoft.directory/conditionalAccessPolicies/delete

    Why it's wrong here

    Deleting a Conditional Access policy is a destructive action that may not be necessary for managing existing policies; typical management tasks involve modifying configurations, not removing them. Since the question asks for the two required permissions, delete is not among them because read and update alone are sufficient for the core management workflow. Including delete would expand the security footprint without adding value for this specific task.

  • ✓

    microsoft.directory/conditionalAccessPolicies/update

    Why this is correct

    The update permission is essential because managing Conditional Access policies inherently requires modifying them—for instance, changing conditions, grant controls, or enforcement status. This permission is specifically scoped to alter existing policy objects, making it one of the two key permissions needed. Alongside read, update provides the complete minimal capability set for effective policy management.

  • ✗

    microsoft.directory/conditionalAccessPolicies/create

    Why it's wrong here

    Creating new Conditional Access policies is a separate operation that is not required when the goal is to manage existing policies. The minimal set of read and update covers the vast majority of management activities, and create is only necessary when you need to add a brand-new policy from scratch. Therefore, create is not one of the two required permissions and is an incorrect choice here.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MS-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Refer to the exhibit. You need to ensure that users accessing Exchange Online from unmanaged devices are blocked. What should you modify in the policy?

medium
  • A.Remove the MFA control
  • B.Add the 'approvedClientApp' grant control with OR
  • C.Add a session control for app protection policies
  • ✓ D.Change the operator from OR to AND

Why D: The exhibit shows a conditional access policy with two grant controls: 'Require multi-factor authentication' and 'Require device to be marked as compliant', connected by OR. With OR, users can satisfy either control, so unmanaged devices can still authenticate via MFA alone. Changing the operator to AND forces both MFA and device compliance, blocking access from unmanaged devices that cannot be compliant.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.