Administrators want to enforce multi-factor authentication (MFA) for all users when accessing cloud applications from untrusted networks. They plan to use Azure AD Conditional Access with named locations. Which two components must be configured to meet this requirement? (Select two.)
Trap 1: location policy
A location policy is a named-locations container defining trusted IP ranges or countries; it holds no grant controls itself, so it cannot enforce MFA. It is tempting because named locations are central to the scenario, but the location policy is the correct component when merely defining which networks Conditional Access should treat as trusted.
Trap 2: Conditional Access policy targeting MFA registration
A policy targeting MFA registration governs enrolment in authentication methods, not access enforcement, so it cannot block cloud app sign-ins from untrusted networks. It is tempting because it relates to MFA, but it is the correct choice when requiring users to register methods before accessing resources.
- A
location policy
Why it fails: A location policy is a named-locations container defining trusted IP ranges or countries; it holds no grant controls itself, so it cannot enforce MFA. It is tempting because named locations are central to the scenario, but the location policy is the correct component when merely defining which networks Conditional Access should treat as trusted.
- B
named location for the corporate network
A named location defines the corporate network as a trusted IP range, letting the policy distinguish trusted from untrusted access. Without it, Conditional Access cannot evaluate whether a session originates inside or outside the office, so the MFA condition cannot be scoped correctly.
- C
Conditional Access policy targeting all cloud apps
The Conditional Access policy targeting all cloud apps binds the MFA grant control to every application, satisfying the requirement to enforce MFA across cloud apps. Combined with the named location condition, it applies only when access originates from untrusted networks.
- D
Conditional Access policy targeting MFA registration
Why it fails: A policy targeting MFA registration governs enrolment in authentication methods, not access enforcement, so it cannot block cloud app sign-ins from untrusted networks. It is tempting because it relates to MFA, but it is the correct choice when requiring users to register methods before accessing resources.