MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Your company uses Microsoft Entra ID with hybrid joined devices. You need to enforce multi-factor authentication (MFA) for all cloud app access but want to exclude specific locations (trusted IPs). What is the most efficient way to implement this?
⚠ Common exam trap
MS-102 often tests the confusion between per-user MFA (legacy, limited) and Conditional Access (modern, granular) — candidates who pick per-user MFA miss that CA is the recommended and more capable solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy targeting all cloud apps, requiring MFA, with a condition to exclude trusted IPs
A Conditional Access policy scoped to 'All cloud apps' with a grant control of 'Require multi-factor authentication' and a location condition excluding trusted IPs is the most efficient and granular way to meet the requirement. Conditional Access is the modern, recommended policy engine in Entra ID and supports named locations (trusted IPs) as a first-class condition, so trusted locations bypass MFA while all other access is challenged. This satisfies both the enforcement and exclusion requirements in a single policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Microsoft Intune to enforce MFA for all corporate devices
Why it's wrong here
Intune compliance policies govern device configuration and conditional access grant controls, not MFA enforcement for cloud app sign-ins. They cannot exclude trusted IP ranges from an authentication requirement. Conditional Access policies combine an all-cloud-apps target with a location condition, matching the stated requirement.
- ✗
Enable per-user MFA and exclude trusted IPs in the MFA service settings
Why it's wrong here
Per-user MFA is a legacy toggle that enables or disables the service per account; its trusted-IP setting applies only to legacy authentication and cannot scope enforcement to cloud apps. Conditional Access policies target all cloud apps and exclude named locations directly, which is what the scenario requires.
- ✗
Configure a user risk policy in Microsoft Entra ID Protection to require MFA when risk is medium or higher
Why it's wrong here
User risk policies trigger MFA only when Entra ID Protection detects elevated sign-in risk, so compliant low-risk users reach cloud apps without a second factor. The requirement is unconditional MFA for all cloud app access with named trusted-IP exclusions, which a Conditional Access policy targeting all users and cloud apps, with a location condition, enforces.
- ✓
Create a Conditional Access policy targeting all cloud apps, requiring MFA, with a condition to exclude trusted IPs
Why this is correct
Conditional Access evaluates sign-ins against user, app and location conditions, so a single policy requiring MFA for all cloud apps with trusted IPs excluded satisfies both requirements without per-app configuration or legacy per-user MFA settings.
Go deeper
Related to this question
Learn chapter
Emergency Access (Break-Glass) Accounts
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.