Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

You are configuring a Microsoft Entra Conditional Access policy to require compliant devices for access to Microsoft 365 apps. You need to ensure that the policy applies to all users except those in the 'BreakGlass' group. The BreakGlass group contains emergency access accounts. What should you do?

⚠ Common exam trap

The trap here is mixing up grant controls and session controls; requiring a compliant device is a grant control, not a session control like app enforced restrictions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Conditional Access policy that includes all users and excludes the BreakGlass group, and set the grant control to 'Require device to be marked as compliant'.

To enforce device compliance while excluding emergency access accounts, create a Conditional Access policy that targets all users but excludes the BreakGlass group. Then set the grant control to require the device to be marked as compliant. This ensures that only compliant devices can access Microsoft 365 apps, while emergency accounts remain unaffected. The other options either block emergency accounts, apply session restrictions instead of compliance, or require MFA instead of compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a Conditional Access policy that includes the BreakGlass group and set the grant control to 'Block access'.

    Why it's wrong here

    Including the BreakGlass group and blocking access would prevent emergency accounts from accessing resources, which is the opposite of what is needed. Emergency access accounts must remain accessible even if other policies fail. Blocking them could lead to a lockout situation where administrators cannot regain control. This option directly contradicts the requirement to exclude the BreakGlass group from the compliant device policy.

  • ✗

    Create a Conditional Access policy that includes all users, excludes the BreakGlass group, and set the grant control to 'Require multi-factor authentication'.

    Why it's wrong here

    Requiring multi-factor authentication does not enforce device compliance. MFA is an authentication strength, not a device compliance check. The policy needs to ensure that only compliant devices can access Microsoft 365 apps. While MFA adds security, it does not satisfy the requirement for device compliance. Thus, this option is incorrect for the given scenario.

  • ✓

    Create a Conditional Access policy that includes all users and excludes the BreakGlass group, and set the grant control to 'Require device to be marked as compliant'.

    Why this is correct

    Conditional Access policies allow you to include all users and then exclude specific groups, such as the BreakGlass group. This ensures that emergency access accounts are not blocked by the policy. Setting the grant control to require a compliant device enforces the device compliance requirement for all other users. This is the correct and recommended approach to avoid locking out emergency accounts.

  • ✗

    Create a Conditional Access policy that includes all users and excludes the BreakGlass group, and set the session control to 'Use app enforced restrictions'.

    Why it's wrong here

    App enforced restrictions are used to limit access for unmanaged devices, such as allowing only web access without download. This does not enforce device compliance; it only applies restrictions. The requirement is to require compliant devices, which is a grant control, not a session control. Therefore, this option does not meet the stated need and would not enforce compliance.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.