MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
You are configuring a Microsoft Entra Conditional Access policy to require compliant devices for access to Microsoft 365 apps. You need to ensure that the policy applies to all users except those in the 'BreakGlass' group. The BreakGlass group contains emergency access accounts. What should you do?
⚠ Common exam trap
The trap here is mixing up grant controls and session controls; requiring a compliant device is a grant control, not a session control like app enforced restrictions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy that includes all users and excludes the BreakGlass group, and set the grant control to 'Require device to be marked as compliant'.
To enforce device compliance while excluding emergency access accounts, create a Conditional Access policy that targets all users but excludes the BreakGlass group. Then set the grant control to require the device to be marked as compliant. This ensures that only compliant devices can access Microsoft 365 apps, while emergency accounts remain unaffected. The other options either block emergency accounts, apply session restrictions instead of compliance, or require MFA instead of compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a Conditional Access policy that includes the BreakGlass group and set the grant control to 'Block access'.
Why it's wrong here
Including the BreakGlass group and blocking access would prevent emergency accounts from accessing resources, which is the opposite of what is needed. Emergency access accounts must remain accessible even if other policies fail. Blocking them could lead to a lockout situation where administrators cannot regain control. This option directly contradicts the requirement to exclude the BreakGlass group from the compliant device policy.
- ✗
Create a Conditional Access policy that includes all users, excludes the BreakGlass group, and set the grant control to 'Require multi-factor authentication'.
Why it's wrong here
Requiring multi-factor authentication does not enforce device compliance. MFA is an authentication strength, not a device compliance check. The policy needs to ensure that only compliant devices can access Microsoft 365 apps. While MFA adds security, it does not satisfy the requirement for device compliance. Thus, this option is incorrect for the given scenario.
- ✓
Create a Conditional Access policy that includes all users and excludes the BreakGlass group, and set the grant control to 'Require device to be marked as compliant'.
Why this is correct
Conditional Access policies allow you to include all users and then exclude specific groups, such as the BreakGlass group. This ensures that emergency access accounts are not blocked by the policy. Setting the grant control to require a compliant device enforces the device compliance requirement for all other users. This is the correct and recommended approach to avoid locking out emergency accounts.
- ✗
Create a Conditional Access policy that includes all users and excludes the BreakGlass group, and set the session control to 'Use app enforced restrictions'.
Why it's wrong here
App enforced restrictions are used to limit access for unmanaged devices, such as allowing only web access without download. This does not enforce device compliance; it only applies restrictions. The requirement is to require compliant devices, which is a grant control, not a session control. Therefore, this option does not meet the stated need and would not enforce compliance.
Go deeper
Related to this question
Learn chapter
Entra ID Administration
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.