PL-900 Multi-factor authentication (MFA) Practice Question
An administrator is managing a Power Platform environment that uses Microsoft Entra ID for authentication. The company wants to enforce multi-factor authentication (MFA) for all users accessing Power Apps. Which TWO configurations should the administrator implement? (Choose two.)
⚠ Common exam trap
The trap is that candidates may think only one method works (e.g., only the Entra ID conditional access policy), but the Power Platform admin center also provides a setting to require MFA for the environment. The question asks for two configurations, so you must select both valid approaches.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the environment's 'User authentication' setting to 'Require MFA' in Power Platform admin center
To enforce MFA for all users accessing Power Apps, two configurations should be implemented: enabling the 'Require MFA' setting in the Power Platform admin center (Option A) and creating a conditional access policy in Microsoft Entra ID (Option D). The admin center provides a direct setting under environment User Authentication to require MFA. Option D provides organization-wide enforcement by applying a conditional access policy to all cloud apps. Option C is incorrect because there is no separate 'Require MFA' option under environment security settings; the only built-in MFA toggle is the User Authentication setting. Options B and E are irrelevant.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the environment's 'User authentication' setting to 'Require MFA' in Power Platform admin center
Why this is correct
Correct. The Power Platform admin center's 'User authentication' setting allows you to require MFA for users accessing the environment.
- ✗
Disable security group membership for the environment
Why it's wrong here
Incorrect. Disabling security group membership does not enforce MFA.
- ✗
Enable MFA in the environment's security settings under 'Require MFA'
Why it's wrong here
Incorrect. There is no separate 'Require MFA' option under environment security settings. The only direct MFA setting is under 'User authentication'.
- ✓
Create a conditional access policy in Microsoft Entra ID that requires MFA for all cloud apps
Why this is correct
Correct. A conditional access policy in Microsoft Entra ID can require MFA for all cloud apps, including Power Apps.
- ✗
Assign the 'System Administrator' role to all users
Why it's wrong here
Incorrect. Assigning the System Administrator role does not enforce MFA.
Go deeper
Related to this question
About these practice questions
This PL-900 question is part of Courseiva's 904-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.