MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Which TWO of the following are valid conditions that can be used in a Microsoft Entra ID conditional access policy? (Choose two.)
⚠ Common exam trap
Many candidates confuse 'Network location' with the valid 'Locations' condition, or assume that application sensitivity labels (which are part of Microsoft Purview) can be used directly in Conditional Access policies, when in fact they are not a supported condition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sign-in risk
Sign-in risk (B) and user risk (D) are both valid conditions in Microsoft Entra ID Conditional Access policies. These risk levels are calculated by Microsoft Entra ID Protection using real-time signals such as anonymous IP addresses, atypical travel, or leaked credentials, and can be used to trigger policies like requiring multi-factor authentication or blocking access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network location
Why it's wrong here
Network location is not a recognized condition in Microsoft Entra Conditional Access. The actual condition is called 'Locations', which uses named locations defined by IPv4/IPv6 ranges or countries/regions. 'Network location' is too vague and does not correspond to any condition type in the Conditional Access policy editor, so it cannot be selected.
- ✓
Sign-in risk
Why this is correct
Sign-in risk is a valid condition in Microsoft Entra Conditional Access. It evaluates the probability that the current authentication attempt is compromised, based on real-time risk detections from Identity Protection (such as impossible travel, anonymous IP, or leaked credentials). Administrators can configure policies to block access or require additional controls when the sign-in risk level is Low, Medium, or High.
- ✗
Application sensitivity label
Why it's wrong here
Application sensitivity label is not a condition in Microsoft Entra Conditional Access. Sensitivity labels are part of information protection and govern data classification, encryption, and labeling on documents and emails, not authentication or access decisions. Conditional Access conditions include cloud apps, users, locations, device state, sign-in risk, and user risk, but not labels applied to applications or their content.
- ✓
User risk
Why this is correct
User risk is a valid condition in Microsoft Entra Conditional Access. It reflects the probability that a user’s account has been compromised, based on historical risk detections associated with that user, such as leaked credentials or previous high-risk sign-ins. It differs from sign-in risk, which focuses on the current authentication attempt, whereas user risk is persistent across sessions and can trigger block or remediation policies like password reset.
- ✗
Device manufacturer
Why it's wrong here
Device manufacturer is not a standalone condition in Microsoft Entra Conditional Access. While the 'Filter for devices' preview feature permits matching on device attributes such as deviceManufacturer, this is nested under the 'Device state' condition, not a separate top-level condition. Therefore, 'Device manufacturer' is not an option in the basic condition list and cannot be selected directly.
Go deeper
Related to this question
Learn chapter
SharePoint External Sharing and Guest Policies
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.