MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Your company uses Microsoft Entra ID. You need to restrict access to a critical application to only users who are in a specific security group and are signing in from a trusted location. You configure a conditional access policy with the following conditions: users (the security group), cloud apps (the critical application), conditions (locations: trusted IP ranges). However, users in the security group are still able to access the app from untrusted locations. What is the most likely reason?
⚠ Common exam trap
Candidates often assume a Conditional Access policy automatically enforces its conditions once configured, overlooking the critical distinction between report-only mode (evaluation only) and on/enforce mode (evaluation + enforcement).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy is in report-only mode
When a Conditional Access policy is in report-only mode, it evaluates the conditions and logs the result but does not enforce any access controls (grant or block). This explains why users in the security group can still access the app from untrusted locations—the policy is not actively blocking or requiring MFA/location compliance. Report-only mode is commonly used for testing before enabling enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy is configured as a block policy but is overridden by another policy
Why it's wrong here
Conditional Access policies do not override one another; when multiple policies apply, all grant controls are combined and any block control takes precedence. Since the policy is explicitly set as a block policy, it would still block regardless of other policies. Therefore, another policy overriding the block is not a valid explanation for access continuing to be granted.
- ✗
The cloud app is not correctly assigned to the policy
Why it's wrong here
The Cloud apps assignment controls which apps the policy applies to, and if the target application is selected, the policy will be triggered for those sign-ins. A misconfigured app assignment would cause the policy to simply not apply, yet the stem indicates the app is selected. Report-only mode, not the assignment, is what prevents the policy from acting after it is triggered.
- ✗
The policy uses session controls instead of grant controls
Why it's wrong here
Session controls, such as sign-in frequency or app session policies, do not deny access; they only govern the session after authentication. In contrast, a block policy uses the 'Block access' grant control, which explicitly prevents sign-in. Since the policy in question is meant to block but fails to do so, the issue cannot be a substitution of session controls for grant controls; rather, the policy's enforcement mode is set to report-only.
- ✓
The policy is in report-only mode
Why this is correct
Report-only mode evaluates a Conditional Access policy and writes the results to the Identity Protection logs without enforcing any of its configured controls. For a block policy, report-only means the intended block is never applied, and access is allowed exactly as if the policy did not exist. This is the classic default misconfiguration that makes a block policy appear ineffective during testing.
Go deeper
Related to this question
Learn chapter
OneDrive Sharing Policies and External Access
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.