MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Your company is implementing Microsoft Entra Conditional Access. You need to require multifactor authentication (MFA) for all users except those accessing from the corporate office. Which TWO components do you need?
⚠ Common exam trap
Test-takers frequently think a separate MFA registration policy (Option D) or Identity Protection (Option E) can handle location-based exclusions, but neither supports excluding Named Locations; only a Conditional Access policy with the 'Exclude' condition on Named Locations can achieve this.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policy configured with grant control requiring MFA and excluding Named Locations
To require MFA for all users except those accessing from the corporate office, you need a Conditional Access policy that grants access only if MFA is completed, and you must exclude the corporate office location. The 'Named Locations' configuration defines the corporate office IP ranges or trusted locations, and the Conditional Access policy uses that exclusion. Together, these two components enforce the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Intune compliance policies
Why it's wrong here
Intune compliance policies assess device attributes such as jailbreak status, BitLocker encryption, minimum OS version, and password configuration, then mark devices as compliant or noncompliant. A Conditional Access policy can require a compliant device, but this control looks at device health, not the user's current network location or IP address. Therefore, it cannot decide when to drop MFA based on whether a sign-in originates from the corporate office. The location signal must come from Named Locations evaluated by Conditional Access.
- ✓
Conditional Access policy configured with grant control requiring MFA and excluding Named Locations
Why this is correct
To enforce MFA everywhere except the corporate office, you create a Conditional Access policy assigned to the target users and cloud apps, add your trusted corporate IP ranges as a Named Location, and set that location in the Exclude condition. Then, in Grant, you select 'Require multifactor authentication.' For sign-ins from any IP address that does not match the excluded Named Location, the grant control is applied and MFA is required; for sign-ins from the corporate location, the exclusion prevents MFA from being required. This is the actual policy object that implements the stated requirement.
- ✓
Named Locations configuration
Why this is correct
The Named Locations configuration is the prerequisite data that stores the corporate office's public IPv4 addresses (and optionally IPv6 or countries) in Microsoft Entra ID, either as trusted or untrusted locations. Without this object, Conditional Access has no way to know which IP ranges represent 'the corporate office' and cannot exclude that location. Creating the Named Location is technically correct as part of the solution, but it only has effect after the Conditional Access policy references it in the location condition.
- ✗
Microsoft Entra multifactor authentication registration policy
Why it's wrong here
The MFA registration policy (registration campaign) in Microsoft Entra ID requires users to register their authentication methods, like the Authenticator app or phone number, within a set time frame. It does not evaluate sign-in location or session context, and a user who has registered still might not be prompted for MFA at every non-office sign-in. This policy sets up the users' credentials but lacks the 'excluding Named Locations' logic found in the actual Conditional Access policy. Thus, registration alone does not enforce location-based MFA.
- ✗
Microsoft Entra Identity Protection
Why it's wrong here
Microsoft Entra Identity Protection makes risk-based decisions using user risk and sign-in risk signals, such as Anomalous Token, Impossible Travel, or Atypical Sourcing, to trigger policies requiring MFA or blocked access. A risk policy can be configured to respond with MFA when a sign-in is deemed risky, but it does not provide a location-based bypass that consistently skips MFA for a trusted office IP range. Identity Protection's 'Impossible Travel' may even flag certain office-originated sign-ins depending on historical patterns. It cannot implement the deterministic 'MFA everywhere except our office' rule described in the scenario.
Go deeper
Related to this question
Learn chapter
PHS vs Pass-Through Authentication vs Federation
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.