Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your company has a Microsoft 365 E5 subscription and uses Microsoft Entra ID. Users report that they are frequently prompted for multi-factor authentication (MFA) even after signing in successfully. You want to minimize these prompts while maintaining security. What should you configure?

⚠ Common exam trap

A common mix-up: candidates confuse session controls (which manage MFA prompt frequency) with risk-based policies or per-user MFA states, assuming that disabling MFA or modifying risk policies will reduce prompts, when in fact session management is the precise control for this scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Authentication Session Management

Configuring Authentication Session Management in a Conditional Access policy allows you to control how often users are prompted for MFA by setting the sign-in frequency (e.g., every 24 hours) or persistent browser session (e.g., 'Remember MFA for 14 days'). This directly addresses the user complaint of frequent MFA prompts while maintaining security by enforcing reauthentication at defined intervals.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure Authentication Session Management

    Why this is correct

    Configuring Authentication Session Management within a Conditional Access policy allows you to set sign-in frequency (for example, every 12 hours) and persistent browser sessions. This controls the token lifetime so that users are not repeatedly prompted for MFA within the defined window, directly reducing authentication prompts while retaining security.

  • ✗

    Modify the Conditional Access policy to require MFA for all apps

    Why it's wrong here

    Modifying the Conditional Access policy to require MFA for all apps would expand the scope of MFA enforcement to every application, so a user would be challenged each time they access an app that does not have an existing session. This increases the number of MFA prompts rather than reducing them, because it does not alter session lifetime or sign-in frequency.

  • ✗

    Change the per-user MFA state to Disabled

    Why it's wrong here

    Changing the per-user MFA state to Disabled is the legacy control that turns off MFA enforcement for that account, leaving it protected only by the password. While this would eliminate MFA prompts, it is a severe security regression and is not a valid solution. Additionally, if MFA is enforced via Conditional Access, this setting has no effect, so prompts would not necessarily stop.

  • ✗

    Adjust Identity Protection user risk policy

    Why it's wrong here

    Adjusting the Identity Protection user risk policy only changes the thresholds for automatically responding to suspicious sign-in attempts, such as blocking access or requiring MFA when risk is high. It does not govern session lifetime or sign-in frequency, so it would not reduce MFA prompts for legitimate user activity. Therefore, it is an unrelated control that cannot solve the problem.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.