Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

You are the Microsoft 365 administrator for a company that uses Microsoft Entra ID P2. The security team wants to require members of the 'Finance' group to use multifactor authentication (MFA) when they access any cloud app from outside the corporate network. You create a Conditional Access policy and assign it to the Finance group. You need to configure the policy to meet the requirement while minimizing impact on other users. What should you do?

⚠ Common exam trap

The trap here is assuming that report-only mode enforces MFA or that security defaults can be scoped to a group.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a named location for the corporate network and exclude it from the policy.

The requirement is to require MFA for Finance group members only when they access cloud apps from outside the corporate network. This is achieved by creating a named location for the corporate network and excluding it from the Conditional Access policy. The policy then applies only to sign-ins from other locations, enforcing MFA externally without impacting internal users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the policy to report-only mode and monitor the sign-in logs.

    Why it's wrong here

    Report-only mode evaluates the policy but does not enforce MFA. It is useful for testing, but the requirement is to require MFA, so this does not meet the goal. It would allow Finance users to sign in without MFA, leaving the security gap open. Monitoring alone does not enforce the control.

  • ✗

    Configure the policy to apply to all users and all cloud apps, and require MFA.

    Why it's wrong here

    Applying to all users and all cloud apps would enforce MFA for everyone, including users outside Finance and internal access. This exceeds the requirement and could disrupt other users. The goal is to target only Finance group members when they are off the corporate network, so this broad scope is incorrect.

  • ✓

    Create a named location for the corporate network and exclude it from the policy.

    Why this is correct

    A named location defines trusted IP ranges. By excluding the corporate network, the policy applies only when Finance users are outside that network, satisfying the requirement to require MFA externally while not affecting internal access. This is the standard method to scope Conditional Access by network location.

  • ✗

    Enable security defaults in Microsoft Entra ID.

    Why it's wrong here

    Security defaults enforce MFA for all users, but they cannot be scoped to a specific group or condition like network location. They also override Conditional Access policies. This would not meet the granular requirement and would affect all users, so it is not the right choice.

Go deeper

Related to this question

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.