Courseiva
mediumMultiple Select

MS-102 Practice Question: Contoso wants to require multi-factor…

Contoso wants to require multi-factor authentication (MFA) for all users when accessing cloud applications from any network except the corporate headquarters (trusted IP range). They plan to use Microsoft Entra Conditional Access. Which two components must be configured to achieve this requirement? (Select all that apply.)

⚠ Common exam trap

Candidates often confuse the MFA registration policy (which only ensures users have registered MFA methods) with the Conditional Access policy that actually enforces MFA based on location conditions, leading them to incorrectly select Option D as a required component.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access policy targeting all users and cloud apps, with conditions for locations

A Conditional Access policy must be created to enforce MFA based on location conditions. The policy targets all users and cloud apps, and uses the 'locations' condition to exclude the trusted IP range (corporate headquarters) while requiring MFA for all other locations. This ensures MFA is triggered only when access originates from outside the trusted network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conditional Access policy targeting all users and cloud apps, with conditions for locations

    Why this is correct

    A Conditional Access policy is the operational enforcement point for MFA. By targeting all users and cloud apps and adding a location condition, you can require MFA for every sign-in that occurs outside defined trusted networks. This policy works by evaluating the user's IP address and applying an MFA challenge when the location is untrusted, which directly satisfies the goal of enforcing MFA universally. It also allows the use of 'report-only' mode for pre-testing before enforcement.

  • ✓

    named location defining the corporate headquarters' trusted IP ranges

    Why this is correct

    A named location is a predefined set of IP address ranges or geopolitical regions in Microsoft Entra ID designed to be referenced by Conditional Access policies. For this scenario, the corporate headquarters' trusted IP ranges must be defined as a named location so the Conditional Access policy can identify traffic that originates from inside the office and exempt it, or treat it as trusted. Without this named location, the policy would treat all IPs the same, making it impossible to condition MFA based on location. Therefore, it is a necessary companion to the Conditional Access policy.

  • ✗

    An Identity Protection user risk policy

    Why it's wrong here

    An Identity Protection user risk policy is fundamentally different because it triggers on user-risk signals such as leaked credentials, unusual sign-in behavior, or impossible travel, rather than on the network location of the sign-in. It may enforce actions like requiring a password change or blocking access, but it does not apply a universal MFA requirement to all users and cloud apps. Because risk is evaluated probabilistically and only after certain anomalies are detected, it cannot serve as the primary mechanism for a location-based MFA requirement.

  • ✗

    An MFA registration policy requiring users to register for MFA

    Why it's wrong here

    The MFA registration policy ensures all users have enrolled an authentication method (such as a phone number, authenticator app, or security key), which is a necessary prerequisite for MFA to function. However, this policy never triggers an actual MFA challenge during a sign-in. Even if every user is registered, they will only be prompted for MFA when a separate Conditional Access policy demands it. Thus, while registration is essential, it is not sufficient to enforce MFA for all users and cloud apps based on location.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.