Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Exhibit

Refer to the exhibit.

PowerShell Output:
Get-MgPolicyCrossTenantAccessPolicyDefault -Default

Id                                   : default
DisplayName                          : Default policy
IsServiceDefault                     : True
B2BCollaborationInbound              : @{Applications=; UsersAndGroups=; Organizations=}
B2BCollaborationOutbound             : @{Applications=; UsersAndGroups=; Organizations=}
B2BDirectConnectInbound              : @{Applications=; UsersAndGroups=; Organizations=}
B2BDirectConnectOutbound             : @{Applications=; UsersAndGroups=; Organizations=}
InboundTrust                          : @{IsMfaAccepted=$false; IsCompliantDeviceAccepted=$false; IsHybridAzureADJoinedDeviceAccepted=$false}

You are examining the default cross-tenant access policy for your Microsoft Entra ID tenant. Based on the exhibit, which statement is true?

⚠ Common exam trap

Many candidates assume 'Trust MFA from external tenants' is enabled by default, but Microsoft deliberately leaves it disabled to enforce the resource tenant's own MFA policies, requiring external users to reauthenticate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

External users must always reauthenticate even if their home tenant requires MFA.

The default cross-tenant access policy in Microsoft Entra ID includes a setting that, when enabled, requires external users to satisfy MFA requirements from their home tenant. However, the exhibit shows that the 'Trust MFA from external tenants' option is not selected, meaning Entra ID will not accept MFA claims from the external user's home tenant. As a result, external users must always reauthenticate with MFA, even if their home tenant already enforced MFA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Your users can use their Microsoft Authenticator app to sign in to partner tenants.

    Why it's wrong here

    The default cross-tenant access policy controls integration and trust with external organizations, but it does not contain any setting that dictates or provisions Microsoft Authenticator for your users when they sign in to partner tenants. Authentication method selection is governed by the user's home tenant and the target tenant's authentication policies, not by cross-tenant access settings. The available settings are limited to inbound trust claims, outbound user restrictions, and B2B collaboration/direct connect rules, so the Authenticator app is not a configurable item here.

  • ✗

    B2B direct connect is enabled for all external organizations.

    Why it's wrong here

    The inbound direct connect section of the default policy is empty, meaning no B2B direct connect trust relationships are configured for any external organization. B2B direct connect is not enabled by default for all organizations; it requires explicit per-tenant configuration through organizational settings, and an empty inbound direct connect setting indicates that external organizations cannot directly access your Teams/SharePoint resources via this mechanism. Therefore, this statement is false.

  • ✓

    External users must always reauthenticate even if their home tenant requires MFA.

    Why this is correct

    With IsMfaAccepted set to $false in the inbound trust settings, the default cross-tenant access policy does not accept MFA claims from external IdPs. This means that even if a user from a partner tenant satisfied MFA in their home tenant, they must complete MFA again when accessing resources in your tenant. Your tenant's conditional access policies are enforced independently of the external tenant's MFA state, ensuring your organization's MFA requirements are always satisfied.

  • ✗

    Compliant device claims from external tenants are trusted.

    Why it's wrong here

    The IsCompliantDeviceAccepted property is set to $false, so device compliance claims from external tenants are explicitly not trusted. As a result, conditional access policies that require a compliant device will not be satisfied by an external device's home-tenant compliance status. The user would need to register or enroll their device in your tenant and meet your device compliance policies to gain access.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.