Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

You are a Microsoft 365 administrator for a multinational company. The security team reports that a large number of failed sign-in attempts are originating from unexpected IP ranges. The company uses Microsoft Entra ID for identity. What should you configure to automatically block these malicious sign-ins?

⚠ Common exam trap

Test-takers frequently confuse Identity Protection risk policies (which block based on user risk) with Conditional Access location-based blocking, or they assume Security defaults or MFA alone can block specific IP ranges, when in fact only a Conditional Access policy with an IP location condition can achieve that granular control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Conditional Access policy to block access from those IP ranges

A Conditional Access policy can explicitly block sign-ins from specific IP ranges. By creating a policy that targets all users or specific users and includes a condition for the named location (the unexpected IP ranges), you can automatically deny authentication requests from those addresses at the Entra ID level, effectively blocking malicious sign-ins before they reach any application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Security defaults in the tenant

    Why it's wrong here

    Security defaults enforce a tenant-wide baseline that includes mandatory Microsoft Entra ID MFA for all users and blocking legacy authentication; however, it is a fixed, non-customizable configuration. It cannot be extended with granular conditions such as source IP address ranges or named locations, so it cannot selectively block traffic from the specified multinational branches. Because security defaults are mutually exclusive with custom Conditional Access policies, you would need to disable them to apply an IP-based block.

  • ✗

    Configure Identity Protection user risk policy to block high-risk users

    Why it's wrong here

    Identity Protection's user risk policy evaluates an algorithmic risk score based on detections like leaked credentials, impossible travel, or unfamiliar sign-in properties, and can take actions such as requiring MFA or blocking high-risk users. It does not provide a condition for matching a request's originating public IP address; instead, risk is attributed to the user/session behavior. To block specific IP ranges, you must use the Locations condition in a Conditional Access policy with a named location.

  • ✗

    Enable Microsoft Entra ID Multi-Factor Authentication for all users

    Why it's wrong here

    Microsoft Entra ID Multi-Factor Authentication is an authentication control that requires a user to prove possession of an additional factor (phone, app, etc.) after primary credentials are validated. It does not evaluate the network location or source IP in the policy decision and will not prevent sign-ins from the specified ranges if users authenticate successfully. MFA is best applied through Conditional Access as a grant control, whereas an IP-based deny requires a separate CA policy with a Location condition and Block access.

  • ✓

    Create a Conditional Access policy to block access from those IP ranges

    Why this is correct

    Create a Conditional Access policy that targets the relevant users and cloud apps, and then add a Locations condition using a named location containing the specific IP ranges. Set the access control to 'Block' and enable the policy to enforce a hard deny for sign-ins originating from those ranges. Because Conditional Access evaluates network location at authentication time, this directly addresses the requirement for blocking specific IP addresses.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.