MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
You are the identity administrator for a Microsoft 365 E5 tenant. The security team wants to enforce Microsoft Entra multifactor authentication (MFA) for all users when they access Microsoft 365 apps from outside the corporate network, but allow seamless access from the corporate office IP range 203.0.113.0/24. You create a Conditional Access policy named 'Require MFA offsite'. Which configuration should you use to meet the requirement?
⚠ Common exam trap
The trap here is assuming that 'Any location' means you cannot exclude the corporate range, when in fact trusted locations are configured as an exclusion within the Locations condition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set Assignments > Users to All users, Cloud apps to Office 365, Conditions > Locations to Any location, exclude the trusted IP 203.0.113.0/24, and Grant to Require multifactor authentication.
The requirement is to require MFA only when users are outside the corporate network. A Conditional Access policy that targets all users and Office 365, applies to any location, excludes the trusted corporate IP range, and grants multifactor authentication achieves this. Excluding the trusted location ensures onsite users are not prompted, while offsite sessions must satisfy the MFA grant control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set Assignments > Users to All users, Cloud apps to Office 365, Conditions > Locations to Any location, and Grant to Require multifactor authentication.
Why it's wrong here
This configuration enforces MFA from every location, including the corporate office range. The requirement explicitly allows seamless access from 203.0.113.0/24, so applying MFA to all locations would cause unnecessary prompts for onsite users and fail to meet the stated goal. You must exclude the trusted range instead of including all locations without exception.
- ✗
Set Assignments > Users to All users, Cloud apps to Office 365, Conditions > Locations to Any location, and Grant to Block access, then create a separate policy to allow the corporate IP range.
Why it's wrong here
Blocking access everywhere and relying on a separate allow policy is overly complex and risky. Conditional Access evaluates policies together, and a block grant would prevent access even from the corporate network unless the second policy explicitly excludes or overrides it. This does not match the requirement to simply require MFA offsite and allow seamless onsite access.
- ✓
Set Assignments > Users to All users, Cloud apps to Office 365, Conditions > Locations to Any location, exclude the trusted IP 203.0.113.0/24, and Grant to Require multifactor authentication.
Why this is correct
This is the correct approach: the policy targets all users and Office 365, applies from any location, but excludes the corporate IP range, so MFA is required only when users are outside the trusted network. The Grant control enforces MFA for the remaining sessions, satisfying the offsite-only requirement without affecting onsite access.
- ✗
Set Assignments > Users to All users, Cloud apps to Office 365, Conditions > Locations to Any location, and Session to Use app enforced restrictions.
Why it's wrong here
App enforced restrictions control session behavior such as limiting downloads in SharePoint and Exchange, not authentication strength. They do not prompt for a second factor, so offsite users would not be challenged with MFA. This setting is used for data protection scenarios, not for enforcing multifactor authentication based on network location.
Go deeper
Related to this question
Learn chapter
OneDrive Sharing Policies and External Access
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.