MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Your organization uses Microsoft Entra ID and has a Conditional Access policy that requires MFA for all external users. However, guest users from a partner organization are being blocked when they try to access a SharePoint Online site. You need to ensure that guest users can access the site without being prompted for MFA if they have already satisfied MFA in their home tenant. What should you configure?
⚠ Common exam trap
Watch out — candidates often confuse the 'authentication methods policy' (which governs allowed MFA methods in your tenant) with the cross-tenant trust setting, leading them to choose Option B, when in fact the correct solution is to enable the trust setting in cross-tenant access settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the trust MFA for external users setting in cross-tenant access settings
The cross-tenant access settings in Microsoft Entra ID include a 'Trust MFA from external tenants' option. When enabled, this setting allows guest users who have already satisfied MFA in their home tenant to access resources in your tenant without being prompted for MFA again. This respects the partner's MFA claims and avoids redundant authentication, which directly resolves the blocking issue caused by the Conditional Access policy requiring MFA for all external users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable MFA requirement for guest users in Conditional Access
Why it's wrong here
Disabling the MFA requirement for guest users in Conditional Access would explicitly exempt B2B collaboration users from the resource tenant's MFA policy, leaving them subject only to their home tenant's security posture. This creates a security gap because the resource tenant cannot guarantee that the home tenant enforces equivalent MFA, and it abandons the principle of enforcing MFA at the resource boundary. The proper fix is not to lift MFA for guests, but to trust MFA already performed in their home tenant via cross-tenant access settings, so you preserve security without duplicate challenges.
- ✗
Configure authentication methods policy to accept MFA from external identities
Why it's wrong here
Configuring the authentication methods policy to accept MFA from external identities misunderstands its purpose: this policy governs which verification methods (e.g., Microsoft Authenticator, FIDO2 security keys, phone numbers) are allowed for users in your own tenant. It cannot ingest or validate MFA claims issued by another tenant's identity provider, nor does it control trust decisions for inbound external users. Trusting MFA from guest users' home tenants is handled by organizational settings in cross-tenant access, specifically the 'Trust MFA from Microsoft Entra ID tenants' checkbox, not by authentication methods.
- ✓
Enable the trust MFA for external users setting in cross-tenant access settings
Why this is correct
Enabling the 'Trust MFA for external users' setting in cross-tenant access settings instructs the resource tenant to accept the multifactor authentication claim that a guest user already satisfied in their home Microsoft Entra tenant. This allows the guest to access applications protected by an MFA Conditional Access policy without being prompted again, streamlining the sign-in experience while maintaining a verified MFA state. The setting applies to inbound B2B collaboration access and can be scoped to all external users or specific tenants, precisely matching the scenario of avoiding redundant MFA challenges.
- ✗
Use B2B direct connect instead of B2B collaboration
Why it's wrong here
Using B2B direct connect instead of B2B collaboration is not an equivalent solution because direct connect is designed specifically for Teams shared channels, not for granting guest users access to corporate applications, files, or other resources protected by Conditional Access policies. Direct connect creates a one-way or mutual connection at the tenant level and requires the user to have a home tenant account, but it does not produce guest user objects or allow the same per-application assignment and MFA trust controls. B2B collaboration is the correct model for inviting external users as guests to your applications, and the cross-tenant trust MFA setting only applies to that collaboration path.
Visual reference
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Conditional Access policy
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.