Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

Which TWO of the following are required to implement Microsoft Entra ID Conditional Access?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID P1 or P2 licenses

Conditional Access requires Microsoft Entra ID P1 or P2 licenses and roles that allow policy management. MFA and Intune are not required for all policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft 365 E5 license

    Why it's wrong here

    Microsoft 365 E5 is not required because Conditional Access relies on Microsoft Entra ID (formerly Azure AD) Premium licensing, not the specific Microsoft 365 suite. While E5 includes Entra ID P2, the same Conditional Access capabilities are available with Entra ID P1, which can be purchased standalone or added to lower-tier Microsoft 365 plans like E3.

  • ✗

    Multifactor Authentication enabled for all users

    Why it's wrong here

    Multifactor Authentication (MFA) being enabled for all users is not a prerequisite for Conditional Access. In fact, Conditional Access is often used to require MFA on specific applications or for specific users; MFA is a grant control you can configure within a policy, not a precondition that must exist before policies can be created or evaluated.

  • ✓

    Microsoft Entra ID P1 or P2 licenses

    Why this is correct

    Conditional Access is a premium feature of Microsoft Entra ID and specifically requires either Microsoft Entra ID P1 or P2 licenses for the users who will be targeted by the policies. Entra ID P1 provides the core policy engine (e.g., MFA, trusted locations, device-based access), while P2 adds risk-based conditional access driven by Identity Protection signals.

  • ✓

    Global Administrator or Conditional Access Administrator role

    Why this is correct

    Creating and managing Conditional Access policies requires sufficient administrative privilege. The Conditional Access Administrator role is the least-privileged role with full management of these policies, and the Global Administrator role also has management rights by virtue of having access to all administrative features. Without one of these roles, a user cannot create, modify, or delete policies.

  • ✗

    Microsoft Intune subscription

    Why it's wrong here

    An Intune subscription is only necessary for Conditional Access scenarios that depend on device state, such as requiring a compliant or domain-joined device as a grant control. For many policies—like requiring MFA for cloud apps or blocking legacy authentication—no Intune license is needed, so Intune is not a general requirement for implementing Conditional Access.

Go deeper

Related to this question

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.