Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Exhibit

Refer to the exhibit.
```json
{
  "displayName": "Block high-risk users from accessing email",
  "conditions": {
    "userRiskLevels": ["high"],
    "applications": {
      "includeApplications": ["Office365"]
    }
  },
  "grantControls": {
    "builtInControls": ["block"]
  }
}
```

Refer to the exhibit. A Conditional Access policy is created in Microsoft Entra ID. The policy targets the Office 365 app (which includes Exchange Online). You have 1000 users assigned. What is the immediate effect of this policy on users who are currently signed in?

⚠ Common exam trap

Microsoft often tests the misconception that Conditional Access policies apply immediately to active sessions, when in fact they only take effect on the next sign-in attempt unless combined with session controls like sign-in frequency or continuous access evaluation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

No immediate effect; users will be blocked on their next sign-in attempt.

Conditional Access policies in Microsoft Entra ID are evaluated at the time of sign-in. They do not terminate existing sessions. Therefore, users who are already signed in will not be affected until their next authentication attempt, at which point the policy's block action will be enforced.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    All high-risk users are immediately blocked from accessing email.

    Why it's wrong here

    Conditional Access policies are evaluated only when a user performs an authentication request, so creating this policy does not instantly affect users who already hold a valid token. The block is applied to the next sign-in attempt, not to the current session; existing tokens remain valid until they expire or are otherwise revoked. Furthermore, the assigned risk condition is user risk, which is an identity-level score, and enforcement still depends on the next authentication event.

  • ✓

    No immediate effect; users will be blocked on their next sign-in attempt.

    Why this is correct

    Conditional Access is an evaluation-time access control: when a user attempts to sign in, Microsoft Entra ID checks the policy conditions—such as the assigned Office 365 app and the user-risk level—and then applies the Block grant control. Immediately after the policy is saved, there is no background task that scans and revokes existing sessions. The policy only takes effect on the next interactive or non-interactive sign-in attempt, at which point a high user-risk user will be denied access. This is why the policy has no immediate effect and the block occurs at the next sign-in.

  • ✗

    The policy is invalid because the Office 365 app does not support block.

    Why it's wrong here

    The Block grant control is a universal Conditional Access control supported by every cloud app that Microsoft Entra Conditional Access can target, including the Office 365 app (which encompasses Exchange Online, SharePoint Online, Teams, and other services). There is no technical limitation that makes a Block policy invalid for Office 365; a policy with a Block control and a user-risk condition is perfectly valid. The policy would simply enforce on the user's next sign-in if the user-risk condition is met. Thus, the assertion that this policy is invalid is incorrect.

  • ✗

    Only users with a sign-in risk of high are blocked.

    Why it's wrong here

    This policy targets User risk, not Sign-in risk, and these are two distinct risk detections in Microsoft Entra ID Protection. Sign-in risk is calculated per authentication attempt to indicate how likely that specific sign-in is compromised, whereas user risk is an aggregate score that reflects the overall likelihood that the user's identity is compromised. As a result, this policy would block users whose User risk is High, even if the current sign-in risk is Low, and it would not block users whose Sign-in risk is High but whose User risk is not. Evaluation and enforcement still happen only at the next sign-in attempt.

Go deeper

Related to this question

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.