You have a Microsoft 365 E5 tenant. Users report that they cannot access the Microsoft 365 admin center (https://admin.microsoft.com). You verify that they have the Global Administrator role assigned. You check the sign-in logs in Microsoft Entra ID and see that the sign-in was blocked by a Conditional Access policy. The policy requires MFA and a compliant device. The users are using personal devices that are not enrolled. What should you do to allow access while maintaining security?
Modifying the Conditional Access policy to exclude the Microsoft 365 admin center from the device compliance requirement, while keeping MFA, is a least-privilege approach. This allows administrators to sign in to the admin center from any device using MFA as a compensating control, but still enforces device compliance for all other cloud apps. This balances security and usability by scoping the exception only to the app that is causing the issue.
Why this answer
It allows users to access the Microsoft 365 admin center by removing the device compliance requirement for that specific cloud app while still enforcing MFA. This maintains security through MFA and avoids blocking access for users on personal, unenrolled devices. Disabling the policy entirely or requiring enrollment would either weaken security or be impractical for personal devices.
Exam trap
The trap here is that candidates may think removing the Global Administrator role (Option C) will bypass the Conditional Access policy, but Conditional Access policies apply to all users regardless of role unless explicitly excluded, and the policy's grant controls are evaluated before role-based access is considered.
How to eliminate wrong answers
Option A is wrong because disabling the Conditional Access policy entirely would remove all security controls (MFA and device compliance) for the admin center, exposing the tenant to unauthorized access. Option B is wrong because asking users to enroll personal devices in Intune may not be feasible or desired for personal devices, and it does not address the immediate access issue without policy modification. Option C is wrong because removing the Global Administrator role does not resolve the Conditional Access block; the policy applies to all users regardless of role, and the users need admin privileges to perform their duties.