Courseiva
mediumMultiple ChoiceObjective-mapped

MS-102 Practice Question: Require that all users accessing a critical cloud…

A company wants to require that all users accessing a critical cloud application for the first time must accept a company terms of use before they are granted access. Which Conditional Access policy grant control should be added?

⚠ Common exam trap

Many exam-takers confuse 'terms of use' with a general compliance or security requirement, leading them to select 'Require device to be marked as compliant' (Option B) because they think device compliance implies policy acceptance, but Conditional Access grant controls are distinct and the terms of use control is the only one that enforces a user-facing acceptance workflow.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Require terms of use

The 'Require terms of use' grant control in a Conditional Access policy is specifically designed to force a user to accept a company's terms of use (TOU) before accessing a cloud application. When this control is enabled, Microsoft Entra ID presents the TOU document to the user on first access, and access is blocked until the user explicitly accepts the terms. This directly meets the requirement of requiring acceptance before granting access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Require multi-factor authentication

    Why it's wrong here

    Requiring multi-factor authentication enforces a second authentication factor, such as a phone call, authenticator app, or FIDO2 key, but that verification does not present or record acceptance of a terms-of-use document. The Azure AD Conditional Access grant 'Require multi-factor authentication' can be combined with terms of use as separate controls, but by itself it only proves possession of additional credentials, not agreement to the application's legal terms.

  • Require device to be marked as compliant

    Why it's wrong here

    Requiring the device to be marked as compliant evaluates the device against Intune compliance policies (OS version, encryption, jailbreak status, etc.) and blocks access for non-compliant hardware. This control is device-centric and does not target the user's consent: a managed, compliant laptop can access the application without ever viewing or accepting a terms-of-use document. It therefore cannot fulfill a requirement that all users explicitly accept the critical application's terms.

  • Require terms of use

    Why this is correct

    The 'Require terms of use' grant control in Azure AD Conditional Access is the only listed option that directly presents a designated Azure AD Terms of Use document to the user at sign-in and requires an explicit Accept action before the session proceeds. Once the user accepts, Azure AD records the acceptance, and the conditional access policy can require reacceptance based on expiration or frequency. This matches the stated requirement precisely because access is gated on the user's affirmative acknowledgement of the terms.

  • Require approved client app

    Why it's wrong here

    The 'Require approved client app' control restricts sign-in to applications listed as approved (for example, Microsoft Outlook, Teams, or other apps with app protection policies) and blocks unapproved client applications. It verifies the client application's identity and compliance with app-level restrictions, but it never displays a terms-of-use document or collects an explicit user consent decision. Consequently, an approved client app grants access without any evidence that the user has accepted the critical application's legal terms.

About these practice questions

Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.