MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
You are the Microsoft 365 administrator for a company that uses Microsoft Entra ID P1 and Microsoft 365 E3. A new security policy requires that when users sign in from outside the corporate network, they must use Microsoft Entra multifactor authentication. However, users signing in from the corporate office network must not be prompted for MFA. The corporate office has a public IP address range of 203.0.113.0/24. You create a named location called 'Corporate Office' with this IP range. What should you do next to meet the requirement?
⚠ Common exam trap
Test-takers frequently confuse the include and exclude conditions in conditional access, or thinking that trusted IPs in per-user MFA can achieve location-based enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a conditional access policy that targets all users and all cloud apps, set the condition to exclude the 'Corporate Office' named location, and require multifactor authentication.
A conditional access policy is the correct tool to enforce MFA based on network location. By excluding a named location containing the corporate IP range, the policy applies MFA only when users sign in from outside that range. This satisfies the security policy while avoiding unnecessary prompts for on-premises users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a conditional access policy that targets all users and all cloud apps, set the condition to exclude the 'Corporate Office' named location, and require multifactor authentication.
Why this is correct
This policy applies MFA to all users and cloud apps but excludes the trusted corporate IP range. Sign-ins from outside the corporate network will not match the exclusion and will trigger MFA, while sign-ins from the office IP range will be excluded and will not require MFA. This meets the requirement exactly.
- ✗
Create a conditional access policy that targets all users and all cloud apps, set the condition to include the 'Corporate Office' named location, and require multifactor authentication.
Why it's wrong here
Including the corporate office location in the policy would require MFA for office users, which is the opposite of what is needed. The policy should exclude the trusted location so that office users are not prompted. This configuration would force MFA on the internal network, failing the requirement.
- ✗
Configure the 'Corporate Office' named location as trusted and enable security defaults.
Why it's wrong here
Security defaults enforce MFA for all users regardless of location and do not support exclusions for trusted IPs. Marking the named location as trusted does not exempt users from MFA under security defaults. This would prompt office users for MFA, violating the requirement. Security defaults also lack the granular control of conditional access.
- ✗
Enable Microsoft Entra multifactor authentication per user for all users, and configure the corporate IP range as trusted IPs in the MFA service settings.
Why it's wrong here
Per-user MFA with trusted IPs is a legacy feature that bypasses MFA for all sign-ins from trusted IPs, but it cannot enforce MFA only for external sign-ins. It also does not support conditional access scenarios and is being deprecated. This approach would not meet the requirement for location-based MFA enforcement.
Go deeper
Related to this question
Learn chapter
Named Locations and Network-Based Policies
Key term
Security policy
A security policy is a formal set of rules and guidelines that an organization establishes to protect its information assets and technology resources.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.