MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Your company is deploying Microsoft Copilot for Microsoft 365. You need to ensure that only users who have completed a specific training course can use Copilot. What should you configure?
⚠ Common exam trap
Watch out — candidates often confuse license-based assignment (Option D) with attribute-based access control, assuming that simply not assigning a license is sufficient, but Microsoft Copilot for Microsoft 365 can still be accessed via trial or free features if not blocked by a Conditional Access policy; the exam tests your understanding that Conditional Access policies are the correct mechanism for enforcing granular, attribute-driven access restrictions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy that requires a custom attribute indicating training completion
A Conditional Access policy can evaluate a custom security attribute assigned to a user or group to enforce access controls. By requiring a custom attribute that indicates training completion, you can block or grant access to Copilot for Microsoft 365 based on that attribute. This approach integrates directly with Microsoft Entra ID's policy engine, allowing granular, attribute-based access control without relying on license assignment or user acceptance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Terms of Use to require acceptance of training policy
Why it's wrong here
Terms of Use in Microsoft Entra ID only captures a one-time acknowledgment of a document; it does not interrogate or verify the user's actual training status. Since an untrained user can click Accept without completing any training, ToU cannot enforce a continuous training requirement for Copilot access. Moreover, ToU provides no integration point to read a training completion record, so it is not a valid substitute for a runtime attribute check.
- ✗
Configure Authentication strengths to require training certificate
Why it's wrong here
Authentication strengths in Conditional Access are designed to mandate specific authentication methods, such as FIDO2, certificate-based authentication, or phishing-resistant MFA. They evaluate how a user proves their identity, not whether they have completed a separate training certificate, which is an organizational compliance fact outside the authentication scope. Even if a certificate is issued, an authentication strength policy has no mechanism to parse or validate that certificate as a training credential for the Copilot application.
- ✓
Create a Conditional Access policy that requires a custom attribute indicating training completion
Why this is correct
This is correct because Microsoft Entra ID supports custom security attributes that can be assigned to user or resource objects, and Conditional Access policies can evaluate these attributes during sign-in. After training is completed, an administrator can set a custom attribute like 'CopilotTrainingCompleted=TRUE' via Graph API or automated workflow; the CA policy then grants access to the Copilot app only when that attribute is present. This provides a true runtime enforcement tied to the user's current directory state, rather than a static license or a one-time agreement.
- ✗
Assign Copilot licenses only to users who completed training
Why it's wrong here
Assigning Copilot licenses only to users who completed training is an initial provisioning decision, not a continuous access enforcement mechanism. Once a user holds a license, they can access Copilot indefinitely, and nothing prevents an untrained user from later gaining a license or prevents a trained user from losing their training status while retaining the license. Licensing also does not evaluate any condition at each sign-in, so it cannot block access if the training certificate expires or is revoked. Conditional Access is required to enforce such dynamic controls at runtime.
Go deeper
Related to this question
Learn chapter
Microsoft Entra Verified ID
Key term
Conditional Access policy
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.