MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
Your company has a Microsoft 365 E5 subscription. You need to configure multi-factor authentication (MFA) for all users. However, the CEO insists that he should not be prompted for MFA when connecting from the corporate office. What should you do?
⚠ Common exam trap
MS-102 often tests the difference between legacy per-user MFA (with its bypass and trusted IP settings) and Conditional Access — the correct modern answer is always Conditional Access with named locations, not per-user bypass.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy that excludes the corporate office named location from requiring MFA.
Conditional Access is the modern, recommended way to enforce MFA in Microsoft 365 E5, and it supports named locations (trusted IPs) that can be excluded from the MFA requirement. Creating a policy that requires MFA for all users but excludes the corporate office named location satisfies the CEO's requirement while keeping MFA enforced everywhere else.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use per-user MFA and set the CEO's account to bypass.
Why it's wrong here
Legacy per-user MFA is an account-level toggle that supports only enable or disable; it has no awareness of network location, so there is no way to designate the corporate office as exempt. Marking the CEO's account to bypass effectively disables MFA for that account from all networks, which fails the requirement to require MFA when the CEO is outside the office. Additionally, per-user MFA bypass does not configure any location-based exclusion for other users or services.
- ✗
Disable MFA for the CEO's account.
Why it's wrong here
Disabling MFA for the CEO's account removes multi-factor authentication entirely, leaving the account protected only by a password no matter where sign-in occurs. This is more dangerous than the intended location-based exception because it exposes the CEO to credential theft and replay attacks from any device or network. The requirement may exempt the corporate office from MFA, but it does not authorize a blanket removal of MFA protection.
- ✗
Configure trusted IPs in the MFA service settings.
Why it's wrong here
MFA trusted IPs are configured in the tenant-wide MFA settings and apply to every user who is enabled for MFA, so they cannot be scoped to just the CEO. If the corporate office IP range is added there, all users in that range—including other employees, guests, or external contractors—will skip MFA, which violates the principle of least privilege. Trusted IPs also lack the granular controls (e.g., per-user exclusion, conditions) that a Conditional Access named location can provide.
- ✓
Create a Conditional Access policy that excludes the corporate office named location from requiring MFA.
Why this is correct
Create a Conditional Access policy that targets the CEO (or all users) and the cloud apps you want to protect, with a condition that requires MFA. In that policy, add a 'named location' for the corporate office IP ranges and exclude it from the policy's assignment, so MFA is not required when the sign-in originated from that range. This is the correct approach because named locations can be defined with trusted IP ranges, and the exclusion is scoped to the policy rather than applied tenant-wide, preserving MFA protection everywhere else.
Go deeper
Related to this question
Learn chapter
Conditional Access Policies
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.