Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Your company has a Microsoft 365 E5 subscription. You need to configure multi-factor authentication (MFA) for all users. However, the CEO insists that he should not be prompted for MFA when connecting from the corporate office. What should you do?

⚠ Common exam trap

MS-102 often tests the difference between legacy per-user MFA (with its bypass and trusted IP settings) and Conditional Access — the correct modern answer is always Conditional Access with named locations, not per-user bypass.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Conditional Access policy that excludes the corporate office named location from requiring MFA.

Conditional Access is the modern, recommended way to enforce MFA in Microsoft 365 E5, and it supports named locations (trusted IPs) that can be excluded from the MFA requirement. Creating a policy that requires MFA for all users but excludes the corporate office named location satisfies the CEO's requirement while keeping MFA enforced everywhere else.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use per-user MFA and set the CEO's account to bypass.

    Why it's wrong here

    Legacy per-user MFA is an account-level toggle that supports only enable or disable; it has no awareness of network location, so there is no way to designate the corporate office as exempt. Marking the CEO's account to bypass effectively disables MFA for that account from all networks, which fails the requirement to require MFA when the CEO is outside the office. Additionally, per-user MFA bypass does not configure any location-based exclusion for other users or services.

  • ✗

    Disable MFA for the CEO's account.

    Why it's wrong here

    Disabling MFA for the CEO's account removes multi-factor authentication entirely, leaving the account protected only by a password no matter where sign-in occurs. This is more dangerous than the intended location-based exception because it exposes the CEO to credential theft and replay attacks from any device or network. The requirement may exempt the corporate office from MFA, but it does not authorize a blanket removal of MFA protection.

  • ✗

    Configure trusted IPs in the MFA service settings.

    Why it's wrong here

    MFA trusted IPs are configured in the tenant-wide MFA settings and apply to every user who is enabled for MFA, so they cannot be scoped to just the CEO. If the corporate office IP range is added there, all users in that range—including other employees, guests, or external contractors—will skip MFA, which violates the principle of least privilege. Trusted IPs also lack the granular controls (e.g., per-user exclusion, conditions) that a Conditional Access named location can provide.

  • ✓

    Create a Conditional Access policy that excludes the corporate office named location from requiring MFA.

    Why this is correct

    Create a Conditional Access policy that targets the CEO (or all users) and the cloud apps you want to protect, with a condition that requires MFA. In that policy, add a 'named location' for the corporate office IP ranges and exclude it from the policy's assignment, so MFA is not required when the sign-in originated from that range. This is the correct approach because named locations can be defined with trusted IP ranges, and the exclusion is scoped to the policy rather than applied tenant-wide, preserving MFA protection everywhere else.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.