Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

Exhibit

{
  "policies": [
    {
      "name": "BlockHighRiskSignIns",
      "conditions": {
        "riskLevel": "high"
      },
      "grantControls": {
        "builtInControls": ["block"]
      }
    },
    {
      "name": "RequireMFAForAll",
      "conditions": {
        "users": ["All"],
        "applications": ["All"]
      },
      "grantControls": {
        "builtInControls": ["mfa"]
      }
    }
  ]
}

Refer to the exhibit. An admin configures these two Conditional Access policies in Microsoft Entra ID. A user signs in from a new location with a device that is not compliant and is assigned a high risk level by identity protection. What will happen to the user's sign-in?

⚠ Common exam trap

It's easy for candidates to assume the second policy (requiring MFA) will be applied because the device is non-compliant, but they overlook that the first policy with a 'Block' grant control takes precedence and stops all further policy evaluation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user is blocked from signing in.

The first Conditional Access policy blocks all access for users assigned a high risk level. Since the user is assigned a high risk level by Identity Protection, this policy is triggered first, and because Conditional Access policies are evaluated in order and the first applicable policy that results in a block will prevent further evaluation, the user is blocked from signing in. The second policy requiring MFA for non-compliant devices is never evaluated because the block policy takes precedence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user is granted access because the second policy requires MFA.

    Why it's wrong here

    The statement is false because Conditional Access policies are evaluated as a set, and a grant control such as MFA in a second policy cannot override a block action in the first policy. Since the first policy explicitly blocks high-risk sign-ins, the user is denied even though the second policy would otherwise require MFA. No token is issued, so access is never granted.

  • ✗

    The user is prompted for MFA due to the second policy.

    Why it's wrong here

    The user does not receive an MFA prompt because the second policy's grant controls are never reached. In Conditional Access, when multiple policies apply, a block action takes precedence over grant controls; authentication is stopped before the service triggers MFA. Thus, the high-risk condition causes the session to be terminated at the block policy, and the MFA policy has no effect.

  • ✓

    The user is blocked from signing in.

    Why this is correct

    The user is blocked from signing in because the first Conditional Access policy is configured to block access when sign-in risk is high. Conditional Access aggregates all applicable policies, and a block action overrides any grant controls from other policies. Because the user's session cannot be established, no access is allowed and the sign-in attempt fails.

  • ✗

    The user is allowed access but with session restrictions.

    Why it's wrong here

    The user is not allowed access with session restrictions because session controls are enforced only after the user is granted access. A block policy, however, denies the sign-in before any grant or session control can be applied. Since the high-risk block policy is triggered, the sign-in is terminated entirely, leaving no session to enforce restrictions on.

Go deeper

Related to this question

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.