Enforce MFA for All Users Without Requiring Registration
Your organization uses Microsoft 365 Business Premium with Microsoft Entra ID P1. You have 200 users. You need to enforce multi-factor authentication (MFA) for all users accessing the company's CRM application, which is a third-party SaaS app integrated via SAML. The CRM app does not support modern authentication protocols. You want to use a Microsoft solution that does not require additional licenses. What should you use?
⚠ Common exam trap
Watch out — candidates often assume per-user MFA (Option C) is the only way to enforce MFA for legacy apps, but Conditional Access policies in Microsoft Entra ID P1 can target specific SAML-integrated apps and enforce MFA without requiring modern authentication protocols on the app side.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy targeting the CRM application and require MFA.
Conditional Access policies in Microsoft Entra ID P1 allow you to target specific cloud applications (including third-party SAML-integrated SaaS apps) and enforce MFA. Since the CRM app does not support modern authentication protocols, Conditional Access can still enforce MFA by requiring a compliant domain-joined device or by using app-enforced restrictions; however, the key is that Conditional Access works at the authentication plane and can require MFA even for legacy apps when combined with a capable authentication method like a one-time passcode or Microsoft Authenticator. This solution uses existing Microsoft Entra ID P1 licensing without additional costs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable security defaults in Microsoft Entra ID.
Why it's wrong here
Enable security defaults in Microsoft Entra ID enforces tenant-wide baseline protections, including MFA for all users and all cloud apps, and cannot be scoped to a single application like the CRM. Enabling this setting would disrupt sign-ins for every user rather than just the CRM users, and it lacks the granular, app-specific control that your requirement demands. Security defaults is a one-toggle baseline, not an application-aware policy.
- ✗
Deploy Microsoft Entra application proxy for the CRM app.
Why it's wrong here
Microsoft Entra application proxy is designed to publish on-premises web applications securely via the Microsoft Entra ID cloud service; it is not applicable to SaaS applications such as your CRM. The CRM is a cloud-based SaaS platform, so there is no on-premises infrastructure to bridge, and the proxy itself does not enforce MFA or provide app-level access conditioning. This option is incorrect because it addresses the wrong app category.
- ✗
Configure per-user MFA for users of the CRM app.
Why it's wrong here
Per-user MFA is a legacy configuration that can be enabled per user account, but it forces MFA on every sign-in for that user, across all applications, not just the CRM. It provides no conditions based on application, location, or device, and unlike Conditional Access, it cannot be scoped to a specific app. This approach would over-require MFA and does not meet the need for granular control over CRM access alone.
- ✓
Create a Conditional Access policy targeting the CRM application and require MFA.
Why this is correct
Create a Conditional Access policy that targets the CRM application and requires MFA provides exactly the app-level scoping you need. Conditional Access policies can be assigned to a specific cloud/SaaS application, and when a user accesses that app, the policy evaluates signals and enforces MFA only for that application. Microsoft 365 Business Premium includes Microsoft Entra ID P1, which gives you the license rights to use Conditional Access, making this the correct, modern approach.
Go deeper
Related to this question
Learn chapter
Named Locations and Network-Based Policies
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.