Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

You are the Microsoft 365 administrator for Fabrikam, which has a Microsoft 365 E5 tenant and Microsoft Entra ID P2. The security team wants to require multifactor authentication for all users when they access any cloud app from outside the corporate network, but they do not want to affect users working in the office. You create a Conditional Access policy named CA01. You need to configure the policy to meet the requirements. What should you do?

⚠ Common exam trap

The trap here is assuming that selecting Any location automatically limits the policy to external networks, when in fact Any location includes trusted locations unless you explicitly exclude them.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the Assignments to All users, All cloud apps, and under Conditions configure Locations to include Any location and exclude the corporate network location, then under Access controls set Grant to Require multifactor authentication, and set Enable policy to On.

The requirement is to enforce MFA only for sign-ins originating outside the corporate network. A Conditional Access policy must include All users and All cloud apps as the assignment scope, then use the Locations condition to exclude the trusted corporate network. With the Grant control set to Require multifactor authentication and the policy enabled, external sign-ins are challenged while internal sign-ins remain unaffected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Set the Assignments to All users, All cloud apps, and under Conditions configure Locations to include Any location and exclude the corporate network location, then under Access controls set Grant to Require multifactor authentication, and set Enable policy to On.

    Why this is correct

    Excluding the corporate network location from the Locations condition ensures the policy applies only to sign-ins from outside the trusted network. Setting Grant to Require multifactor authentication enforces MFA for those sign-ins, and enabling the policy makes it active. This precisely matches the requirement to prompt external users while leaving office users unaffected.

  • ✗

    Set the Assignments to All users, All cloud apps, and under Conditions configure Locations to include Any location, then under Access controls set Grant to Require multifactor authentication, and set Enable policy to On.

    Why it's wrong here

    Including Any location means the policy applies to every sign-in regardless of network, so users in the office would also be prompted for MFA. The requirement explicitly excludes office users, so the location condition must be scoped to exclude trusted locations rather than include all locations.

  • ✗

    Set the Assignments to All users, All cloud apps, and under Conditions configure Client apps to Exchange ActiveSync clients and other clients, then under Access controls set Grant to Require multifactor authentication, and set Enable policy to On.

    Why it's wrong here

    The Client apps condition restricts the policy to specific client types, which does not address the network location requirement. Users in the office using those client apps would still be prompted, and users outside the office using other clients would not be covered. This does not meet the stated scoping by location.

  • ✗

    Set the Assignments to All users, All cloud apps, and under Conditions configure Locations to include Any location, then under Access controls set Grant to Require multifactor authentication, and set Enable policy to Report-only.

    Why it's wrong here

    Report-only mode only evaluates and logs policy results without enforcing them, so users would not be prompted for MFA. Additionally, including Any location would also apply to users in the office, which violates the requirement to leave them unaffected. This configuration therefore fails both the enforcement and the scoping requirement.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.