MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
Which TWO of the following are required to implement Microsoft Entra ID Conditional Access?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID P1 or P2 licenses
Conditional Access requires Microsoft Entra ID P1 or P2 licenses and roles that allow policy management. MFA and Intune are not required for all policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft 365 E5 license
Why it's wrong here
Microsoft 365 E5 is not required because Conditional Access relies on Microsoft Entra ID (formerly Azure AD) Premium licensing, not the specific Microsoft 365 suite. While E5 includes Entra ID P2, the same Conditional Access capabilities are available with Entra ID P1, which can be purchased standalone or added to lower-tier Microsoft 365 plans like E3.
- ✗
Multifactor Authentication enabled for all users
Why it's wrong here
Multifactor Authentication (MFA) being enabled for all users is not a prerequisite for Conditional Access. In fact, Conditional Access is often used to require MFA on specific applications or for specific users; MFA is a grant control you can configure within a policy, not a precondition that must exist before policies can be created or evaluated.
- ✓
Microsoft Entra ID P1 or P2 licenses
Why this is correct
Conditional Access is a premium feature of Microsoft Entra ID and specifically requires either Microsoft Entra ID P1 or P2 licenses for the users who will be targeted by the policies. Entra ID P1 provides the core policy engine (e.g., MFA, trusted locations, device-based access), while P2 adds risk-based conditional access driven by Identity Protection signals.
- ✓
Global Administrator or Conditional Access Administrator role
Why this is correct
Creating and managing Conditional Access policies requires sufficient administrative privilege. The Conditional Access Administrator role is the least-privileged role with full management of these policies, and the Global Administrator role also has management rights by virtue of having access to all administrative features. Without one of these roles, a user cannot create, modify, or delete policies.
- ✗
Microsoft Intune subscription
Why it's wrong here
An Intune subscription is only necessary for Conditional Access scenarios that depend on device state, such as requiring a compliant or domain-joined device as a grant control. For many policies—like requiring MFA for cloud apps or blocking legacy authentication—no Intune license is needed, so Intune is not a general requirement for implementing Conditional Access.
Go deeper
Related to this question
Learn chapter
MFA and Conditional Access in M365
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.