Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

You are the identity administrator for a Microsoft 365 E5 tenant. The security team wants to enforce Microsoft Entra multifactor authentication (MFA) for all users when they access Microsoft 365 apps from outside the corporate network, but allow seamless access from the corporate office IP range 203.0.113.0/24. You create a Conditional Access policy named 'Require MFA offsite'. Which configuration should you use to meet the requirement?

⚠ Common exam trap

The trap here is assuming that 'Any location' means you cannot exclude the corporate range, when in fact trusted locations are configured as an exclusion within the Locations condition.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set Assignments > Users to All users, Cloud apps to Office 365, Conditions > Locations to Any location, exclude the trusted IP 203.0.113.0/24, and Grant to Require multifactor authentication.

The requirement is to require MFA only when users are outside the corporate network. A Conditional Access policy that targets all users and Office 365, applies to any location, excludes the trusted corporate IP range, and grants multifactor authentication achieves this. Excluding the trusted location ensures onsite users are not prompted, while offsite sessions must satisfy the MFA grant control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set Assignments > Users to All users, Cloud apps to Office 365, Conditions > Locations to Any location, and Grant to Require multifactor authentication.

    Why it's wrong here

    This configuration enforces MFA from every location, including the corporate office range. The requirement explicitly allows seamless access from 203.0.113.0/24, so applying MFA to all locations would cause unnecessary prompts for onsite users and fail to meet the stated goal. You must exclude the trusted range instead of including all locations without exception.

  • ✗

    Set Assignments > Users to All users, Cloud apps to Office 365, Conditions > Locations to Any location, and Grant to Block access, then create a separate policy to allow the corporate IP range.

    Why it's wrong here

    Blocking access everywhere and relying on a separate allow policy is overly complex and risky. Conditional Access evaluates policies together, and a block grant would prevent access even from the corporate network unless the second policy explicitly excludes or overrides it. This does not match the requirement to simply require MFA offsite and allow seamless onsite access.

  • ✓

    Set Assignments > Users to All users, Cloud apps to Office 365, Conditions > Locations to Any location, exclude the trusted IP 203.0.113.0/24, and Grant to Require multifactor authentication.

    Why this is correct

    This is the correct approach: the policy targets all users and Office 365, applies from any location, but excludes the corporate IP range, so MFA is required only when users are outside the trusted network. The Grant control enforces MFA for the remaining sessions, satisfying the offsite-only requirement without affecting onsite access.

  • ✗

    Set Assignments > Users to All users, Cloud apps to Office 365, Conditions > Locations to Any location, and Session to Use app enforced restrictions.

    Why it's wrong here

    App enforced restrictions control session behavior such as limiting downloads in SharePoint and Exchange, not authentication strength. They do not prompt for a second factor, so offsite users would not be challenged with MFA. This setting is used for data protection scenarios, not for enforcing multifactor authentication based on network location.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.