MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
Your organization is implementing Microsoft Entra ID (formerly Azure AD) for identity management. Users report that they are prompted for multifactor authentication (MFA) every time they sign in, even from trusted devices. What should you configure to reduce MFA prompts while maintaining security?
⚠ Common exam trap
MS-900 often tests the confusion between authentication methods (MFA) and session controls (sign-in frequency), leading candidates to pick Named locations or SSPR when the question is really about reducing reauthentication prompts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the Conditional Access policy to set session control 'Sign-in frequency' to a longer period.
The 'Sign-in frequency' session control in a Conditional Access policy defines how often users must reauthenticate. By extending this period (e.g., to 30 days) for trusted devices, MFA prompts are reduced while Conditional Access still enforces MFA when the session expires or risk conditions change. This directly addresses the symptom of repeated MFA prompts on trusted devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Define trusted IP ranges in Named locations.
Why it's wrong here
Named locations mark IP ranges as trusted, but a trusted location alone does not suppress MFA unless a Conditional Access policy explicitly excludes it from the MFA grant. It is tempting because named locations feed location-based conditions, yet without that policy the per-sign-in prompt persists.
- ✗
Configure self-service password reset (SSPR) to require MFA less often.
Why it's wrong here
SSPR governs password reset authentication, not sign-in MFA frequency, so it cannot reduce prompts during normal logon. It is tempting because SSPR also involves MFA challenges, but it applies only within the password-reset flow; sign-in frequency is controlled by Conditional Access session controls instead.
- ✗
Use Microsoft Entra Privileged Identity Management (PIM) to grant MFA exemption.
Why it's wrong here
PIM governs just-in-time activation of privileged directory roles; it holds no setting that suppresses MFA prompts for standard users on trusted devices. It is tempting because PIM does control authentication requirements, but only for eligible role assignments, not everyday sign-in frequency for the wider workforce.
- ✓
Modify the Conditional Access policy to set session control 'Sign-in frequency' to a longer period.
Why this is correct
Sign-in frequency controls how often users must reauthenticate, so lengthening the interval reduces repeated MFA prompts on trusted devices. This satisfies the requirement to cut prompts while Conditional Access still enforces MFA and device conditions.
Go deeper
Related to this question
Learn chapter
Entra ID Access Reviews
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.