Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your organization uses Microsoft Entra ID. You need to ensure that users can only access company resources from trusted networks. Which Conditional Access condition should you configure?

⚠ Common exam trap

Test-takers frequently confuse 'network location' with 'device compliance' or 'sign-in risk,' leading them to select Device platforms or Sign-in risk instead of the correct Locations condition.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Locations

The Locations condition in a Conditional Access policy allows you to define trusted network locations using named locations (IP ranges or country/region). By configuring a policy that grants access only from these trusted locations, you ensure users can only access company resources from networks you have explicitly approved, such as corporate offices or VPN egress IPs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Sign-in risk

    Why it's wrong here

    The sign-in risk condition in Conditional Access is driven by Microsoft Entra ID Protection and targets the probability that a sign-in attempt is compromised, using signals such as impossible travel, anomalous behavior, or leaked credentials. It allows policies to react to risk levels (low, medium, high) by blocking or requiring MFA, but it does not evaluate the source IP address or geographic location. Therefore, it cannot enforce restrictions based on network location, making it incorrect for this scenario.

  • ✗

    Device platforms

    Why it's wrong here

    The device platforms condition restricts access based on the operating system running on the client device, such as Windows, macOS, iOS, or Android. It is used to grant or block access for specific platforms or to require compliance on certain OS versions, but it has no awareness of where the request originates from. Since the organization needs to control access based on network location, this condition is not applicable.

  • ✗

    Client apps

    Why it's wrong here

    The client apps condition in Conditional Access targets the application category through which a user connects, distinguishing between browser-based web apps, mobile and desktop applications, and legacy authentication protocols. This setting is commonly used to block legacy auth or require additional controls for specific app types, but it does not consider the IP address or geographic origin of the sign-in. As a result, it cannot fulfill a requirement to restrict access based on location.

  • ✓

    Locations

    Why this is correct

    The locations condition is specifically designed to evaluate the network origin of a sign-in request, using named locations that can be defined either as trusted IP address ranges or as countries/regions. This includes the trusted IPs feature in Microsoft Entra ID, which lets you mark corporate office ranges as trusted to bypass MFA or to block access from any other location. Because the organization needs to ensure access based on network location, this is the correct condition to configure in Conditional Access.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.