An organization has multiple Power Platform environments. The security team mandates that all environments must use Microsoft Entra ID conditional access policies to enforce multi-factor authentication. However, one environment hosts a service account that cannot perform interactive logins. What should the administrator do to comply without breaking the service account?
Conditional access applies only to interactive sign-ins, so a non-interactive service account cannot satisfy MFA prompts. Excluding it from the policy preserves the account's workload authentication while the remaining environments stay compliant with the security team's mandate.
Why this answer
Conditional Access policies in Microsoft Entra ID support targeted exclusions for specific users, groups, or service principals. Excluding the non-interactive service account from the MFA-requiring policy allows it to authenticate programmatically (e.g., via client credentials or service principal) without triggering an interactive MFA challenge, while all other users remain protected. This is the standard, supported approach for service accounts that cannot perform interactive logins.
Exam trap
The trap is thinking MFA can be configured 'inside' a Power Platform environment or that isolating the service account in a new environment bypasses tenant-level Conditional Access — CA is enforced at the Entra ID identity layer and applies tenant-wide.
How to eliminate wrong answers
Option A is wrong because creating a new environment does not exempt the service account from tenant-wide Conditional Access policies — CA applies at the identity layer, not per environment. Option B is wrong because service accounts are by design non-interactive; forcing interactive login breaks automation and violates the principle of least disruption. Option D is wrong because disabling MFA for an entire environment is overly broad, removes protection for all users in that environment, and is not how CA policies are scoped (they target identities, not environments).