MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
Exhibit
Refer to the exhibit.
```json
{
"displayName": "Block high-risk users from accessing email",
"conditions": {
"userRiskLevels": ["high"],
"applications": {
"includeApplications": ["Office365"]
}
},
"grantControls": {
"builtInControls": ["block"]
}
}
```Refer to the exhibit. A Conditional Access policy is created in Microsoft Entra ID. The policy targets the Office 365 app (which includes Exchange Online). You have 1000 users assigned. What is the immediate effect of this policy on users who are currently signed in?
⚠ Common exam trap
Microsoft often tests the misconception that Conditional Access policies apply immediately to active sessions, when in fact they only take effect on the next sign-in attempt unless combined with session controls like sign-in frequency or continuous access evaluation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No immediate effect; users will be blocked on their next sign-in attempt.
Conditional Access policies in Microsoft Entra ID are evaluated at the time of sign-in. They do not terminate existing sessions. Therefore, users who are already signed in will not be affected until their next authentication attempt, at which point the policy's block action will be enforced.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All high-risk users are immediately blocked from accessing email.
Why it's wrong here
Conditional Access policies are evaluated only when a user performs an authentication request, so creating this policy does not instantly affect users who already hold a valid token. The block is applied to the next sign-in attempt, not to the current session; existing tokens remain valid until they expire or are otherwise revoked. Furthermore, the assigned risk condition is user risk, which is an identity-level score, and enforcement still depends on the next authentication event.
- ✓
No immediate effect; users will be blocked on their next sign-in attempt.
Why this is correct
Conditional Access is an evaluation-time access control: when a user attempts to sign in, Microsoft Entra ID checks the policy conditions—such as the assigned Office 365 app and the user-risk level—and then applies the Block grant control. Immediately after the policy is saved, there is no background task that scans and revokes existing sessions. The policy only takes effect on the next interactive or non-interactive sign-in attempt, at which point a high user-risk user will be denied access. This is why the policy has no immediate effect and the block occurs at the next sign-in.
- ✗
The policy is invalid because the Office 365 app does not support block.
Why it's wrong here
The Block grant control is a universal Conditional Access control supported by every cloud app that Microsoft Entra Conditional Access can target, including the Office 365 app (which encompasses Exchange Online, SharePoint Online, Teams, and other services). There is no technical limitation that makes a Block policy invalid for Office 365; a policy with a Block control and a user-risk condition is perfectly valid. The policy would simply enforce on the user's next sign-in if the user-risk condition is met. Thus, the assertion that this policy is invalid is incorrect.
- ✗
Only users with a sign-in risk of high are blocked.
Why it's wrong here
This policy targets User risk, not Sign-in risk, and these are two distinct risk detections in Microsoft Entra ID Protection. Sign-in risk is calculated per authentication attempt to indicate how likely that specific sign-in is compromised, whereas user risk is an aggregate score that reflects the overall likelihood that the user's identity is compromised. As a result, this policy would block users whose User risk is High, even if the current sign-in risk is Low, and it would not block users whose Sign-in risk is High but whose User risk is not. Evaluation and enforcement still happen only at the next sign-in attempt.
Go deeper
Related to this question
Learn chapter
App Consent Policies and Admin Consent
Key term
Conditional Access policy
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.