Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your company is deploying Microsoft Copilot for Microsoft 365. You need to ensure that only users who have completed a specific training course can use Copilot. What should you configure?

⚠ Common exam trap

Watch out — candidates often confuse license-based assignment (Option D) with attribute-based access control, assuming that simply not assigning a license is sufficient, but Microsoft Copilot for Microsoft 365 can still be accessed via trial or free features if not blocked by a Conditional Access policy; the exam tests your understanding that Conditional Access policies are the correct mechanism for enforcing granular, attribute-driven access restrictions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Conditional Access policy that requires a custom attribute indicating training completion

A Conditional Access policy can evaluate a custom security attribute assigned to a user or group to enforce access controls. By requiring a custom attribute that indicates training completion, you can block or grant access to Copilot for Microsoft 365 based on that attribute. This approach integrates directly with Microsoft Entra ID's policy engine, allowing granular, attribute-based access control without relying on license assignment or user acceptance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Terms of Use to require acceptance of training policy

    Why it's wrong here

    Terms of Use in Microsoft Entra ID only captures a one-time acknowledgment of a document; it does not interrogate or verify the user's actual training status. Since an untrained user can click Accept without completing any training, ToU cannot enforce a continuous training requirement for Copilot access. Moreover, ToU provides no integration point to read a training completion record, so it is not a valid substitute for a runtime attribute check.

  • ✗

    Configure Authentication strengths to require training certificate

    Why it's wrong here

    Authentication strengths in Conditional Access are designed to mandate specific authentication methods, such as FIDO2, certificate-based authentication, or phishing-resistant MFA. They evaluate how a user proves their identity, not whether they have completed a separate training certificate, which is an organizational compliance fact outside the authentication scope. Even if a certificate is issued, an authentication strength policy has no mechanism to parse or validate that certificate as a training credential for the Copilot application.

  • ✓

    Create a Conditional Access policy that requires a custom attribute indicating training completion

    Why this is correct

    This is correct because Microsoft Entra ID supports custom security attributes that can be assigned to user or resource objects, and Conditional Access policies can evaluate these attributes during sign-in. After training is completed, an administrator can set a custom attribute like 'CopilotTrainingCompleted=TRUE' via Graph API or automated workflow; the CA policy then grants access to the Copilot app only when that attribute is present. This provides a true runtime enforcement tied to the user's current directory state, rather than a static license or a one-time agreement.

  • ✗

    Assign Copilot licenses only to users who completed training

    Why it's wrong here

    Assigning Copilot licenses only to users who completed training is an initial provisioning decision, not a continuous access enforcement mechanism. Once a user holds a license, they can access Copilot indefinitely, and nothing prevents an untrained user from later gaining a license or prevents a trained user from losing their training status while retaining the license. Licensing also does not evaluate any condition at each sign-in, so it cannot block access if the training certificate expires or is revoked. Conditional Access is required to enforce such dynamic controls at runtime.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.