mediumMultiple ChoiceObjective-mapped
MS-102 Practice Question: Wants to enforce that all administrators use a…
An organization wants to enforce that all administrators use a phishing-resistant authentication method (e.g., FIDO2 security keys or Windows Hello for Business) when accessing Microsoft 365 admin portals. Which Microsoft Entra ID feature should be used?
⚠ Common exam trap
Many candidates confuse the generic MFA enforcement of Security defaults or Per-user MFA with the ability to specify a particular authentication method, not realizing that only Conditional Access authentication strength provides the granularity to mandate phishing-resistant methods like FIDO2.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access authentication strength
Conditional Access authentication strength allows administrators to define and enforce specific authentication methods, such as FIDO2 security keys or Windows Hello for Business, which are phishing-resistant. By creating a policy that targets admin roles and requires an authentication strength policy that mandates these methods, the organization can ensure that only phishing-resistant credentials are accepted when accessing Microsoft 365 admin portals. This granular control goes beyond simple MFA enforcement by specifying the exact authentication method required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access authentication strength
Why this is correct
Conditional Access authentication strength is the correct mechanism because it lets you create or use a built-in policy that requires a specific authentication strength, such as "Phishing-resistant MFA" (FIDO2 security keys, Windows Hello for Business, or certificate-based authentication). You apply this policy to a Conditional Access grant control scoped to the Administrator role, which forces every administrator to sign in using only a phishing-resistant method. This is more than just enabling MFA; it actively rejects weaker methods like SMS, voice call, OTP, or authenticator app verification codes, ensuring compliance with the stated requirement.
- ✗
Security defaults
Why it's wrong here
Security defaults are a baseline tenant-level security configuration that enforces MFA for all users, including administrators, but it does not allow any granularity over which authentication methods are permitted. When security defaults are enabled, users can register and use any MFA method offered by default, including SMS, voice call, or one-time passcodes, none of which are considered phishing-resistant. Security defaults are intentionally simple: they cannot be customized with exception groups, scoped conditions, or specific authentication strength requirements. Therefore, they increase overall security but fail to enforce the specific phishing-resistant method requirement for admin accounts.
- ✗
Per-user MFA
Why it's wrong here
Per-user MFA is the legacy MFA configuration where you individually set an enabled or enforced state for a user, and it only controls whether a second factor is needed—not which factor is acceptable. With per-user MFA, an administrator can register and sign in using any method they choose, such as SMS, voice call, mobile app push, or a one-time code, so phishing-resistant compliance cannot be guaranteed. Additionally, this feature is not integrated with Conditional Access policies or authentication strengths, so you cannot restrict the MFA method by role or apply a phishing-resistant policy to a specific admin group. The lack of enforcement granularity makes it inadequate for this requirement.
- ✗
Identity Protection
Why it's wrong here
Identity Protection focuses on risk detection and remediation, not on controlling which authentication method is used. It evaluates sign-in risk or user risk and can trigger MFA through Conditional Access policies, but the MFA challenge it invokes can be satisfied by any method the user has registered, including vulnerable methods like SMS or OTP. Its MFA registration policy simply prompts users to register for MFA; it does not mandate registration of phishing-resistant credentials. While Identity Protection can add risk-based MFA triggers, it cannot enforce a specific phishing-resistant authentication strength across all administrator sign-ins, so it does not meet the requirement on its own.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.