MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
You are the Microsoft 365 administrator for a company that uses Microsoft Entra ID P2. The security team wants to require members of the 'Finance' group to use multifactor authentication (MFA) when they access any cloud app from outside the corporate network. You create a Conditional Access policy and assign it to the Finance group. You need to configure the policy to meet the requirement while minimizing impact on other users. What should you do?
⚠ Common exam trap
The trap here is assuming that report-only mode enforces MFA or that security defaults can be scoped to a group.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a named location for the corporate network and exclude it from the policy.
The requirement is to require MFA for Finance group members only when they access cloud apps from outside the corporate network. This is achieved by creating a named location for the corporate network and excluding it from the Conditional Access policy. The policy then applies only to sign-ins from other locations, enforcing MFA externally without impacting internal users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the policy to report-only mode and monitor the sign-in logs.
Why it's wrong here
Report-only mode evaluates the policy but does not enforce MFA. It is useful for testing, but the requirement is to require MFA, so this does not meet the goal. It would allow Finance users to sign in without MFA, leaving the security gap open. Monitoring alone does not enforce the control.
- ✗
Configure the policy to apply to all users and all cloud apps, and require MFA.
Why it's wrong here
Applying to all users and all cloud apps would enforce MFA for everyone, including users outside Finance and internal access. This exceeds the requirement and could disrupt other users. The goal is to target only Finance group members when they are off the corporate network, so this broad scope is incorrect.
- ✓
Create a named location for the corporate network and exclude it from the policy.
Why this is correct
A named location defines trusted IP ranges. By excluding the corporate network, the policy applies only when Finance users are outside that network, satisfying the requirement to require MFA externally while not affecting internal access. This is the standard method to scope Conditional Access by network location.
- ✗
Enable security defaults in Microsoft Entra ID.
Why it's wrong here
Security defaults enforce MFA for all users, but they cannot be scoped to a specific group or condition like network location. They also override Conditional Access policies. This would not meet the granular requirement and would affect all users, so it is not the right choice.
Go deeper
Related to this question
Learn chapter
Hybrid Modern Authentication
Key term
Conditional Access policy
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.