mediumMultiple ChoiceObjective-mapped
MS-102 Practice Question: Require that all users accessing a critical cloud…
A company wants to require that all users accessing a critical cloud application for the first time must accept a company terms of use before they are granted access. Which Conditional Access policy grant control should be added?
⚠ Common exam trap
Many exam-takers confuse 'terms of use' with a general compliance or security requirement, leading them to select 'Require device to be marked as compliant' (Option B) because they think device compliance implies policy acceptance, but Conditional Access grant controls are distinct and the terms of use control is the only one that enforces a user-facing acceptance workflow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require terms of use
The 'Require terms of use' grant control in a Conditional Access policy is specifically designed to force a user to accept a company's terms of use (TOU) before accessing a cloud application. When this control is enabled, Microsoft Entra ID presents the TOU document to the user on first access, and access is blocked until the user explicitly accepts the terms. This directly meets the requirement of requiring acceptance before granting access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require multi-factor authentication
Why it's wrong here
Requiring multi-factor authentication enforces a second authentication factor, such as a phone call, authenticator app, or FIDO2 key, but that verification does not present or record acceptance of a terms-of-use document. The Azure AD Conditional Access grant 'Require multi-factor authentication' can be combined with terms of use as separate controls, but by itself it only proves possession of additional credentials, not agreement to the application's legal terms.
- ✗
Require device to be marked as compliant
Why it's wrong here
Requiring the device to be marked as compliant evaluates the device against Intune compliance policies (OS version, encryption, jailbreak status, etc.) and blocks access for non-compliant hardware. This control is device-centric and does not target the user's consent: a managed, compliant laptop can access the application without ever viewing or accepting a terms-of-use document. It therefore cannot fulfill a requirement that all users explicitly accept the critical application's terms.
- ✓
Require terms of use
Why this is correct
The 'Require terms of use' grant control in Azure AD Conditional Access is the only listed option that directly presents a designated Azure AD Terms of Use document to the user at sign-in and requires an explicit Accept action before the session proceeds. Once the user accepts, Azure AD records the acceptance, and the conditional access policy can require reacceptance based on expiration or frequency. This matches the stated requirement precisely because access is gated on the user's affirmative acknowledgement of the terms.
- ✗
Require approved client app
Why it's wrong here
The 'Require approved client app' control restricts sign-in to applications listed as approved (for example, Microsoft Outlook, Teams, or other apps with app protection policies) and blocks unapproved client applications. It verifies the client application's identity and compliance with app-level restrictions, but it never displays a terms-of-use document or collects an explicit user consent decision. Consequently, an approved client app grants access without any evidence that the user has accepted the critical application's legal terms.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Conditional Access policy
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.