Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

An administrator needs to restrict access to Microsoft 365 admin centers based on user location. Which Microsoft Entra ID feature should they configure?

⚠ Common exam trap

Candidates often confuse Identity Protection (which also uses location signals for risk detection) with Conditional Access, but Identity Protection does not enforce access policies—it only provides risk assessments that Conditional Access can consume.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access

Conditional Access is the correct feature because it allows administrators to enforce policies that grant or block access to Microsoft 365 admin centers based on conditions such as user location (IP address ranges or countries). By configuring a Conditional Access policy with a location condition, you can restrict access to sensitive admin portals like the Microsoft 365 admin center or Exchange admin center to trusted networks only.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conditional Access

    Why this is correct

    Conditional Access is the Microsoft Entra ID policy engine that blocks or grants access by evaluating conditions such as user, device, application, risk, and location. You can define a named location based on IP ranges or country/geo coordinates and set an access control to 'Block access' or 'Require MFA' when users connect from certain regions. This is the directly intended mechanism for restricting Microsoft 365 access based on location.

  • ✗

    Identity Protection

    Why it's wrong here

    Identity Protection detects potential vulnerabilities and risk signals like anonymous IP addresses, impossible travel, and leaked credentials, but its output is a risk level, not a location enforcement. It can trigger self-service password reset or MFA challenges as remediation actions, yet these actions depend on a Conditional Access policy to be applied. Therefore, it cannot itself restrict access from specific locations; it only provides risk data.

  • ✗

    Entra ID Governance

    Why it's wrong here

    Entra ID Governance focuses on access lifecycle management, including access reviews, entitlement packages, and certification of group memberships. It ensures that users have the appropriate access for the right duration, but it has no location condition or network-based rule engine. It is not designed to block or allow sign-ins based on geographic or IP-based criteria.

  • ✗

    Privileged Identity Management (PIM)

    Why it's wrong here

    Privileged Identity Management (PIM) manages just-in-time, time-bound activation of privileged administrator roles with workflows for approval and audit. It governs who can hold elevated permissions and when, not the network or geographic location from which regular users access Microsoft 365. Thus, it is unrelated to restricting access based on location.

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.