Courseiva

Configuring Azure App Service Authentication and Conditional Access for MFA and IP Restrictions

You are designing a secure access strategy for Azure App Service web applications. The requirements are: use Microsoft Entra ID for authentication, restrict access to specific IP ranges, and require multi-factor authentication (MFA) for all users. Which two components should you configure? (Choose two.)

Quick Answer

The answer is to configure Azure App Service authentication to use Azure AD and create a Conditional Access policy in Microsoft Entra ID that requires MFA and restricts IP ranges. This combination works because App Service authentication delegates user identity verification to Azure AD, while Conditional Access acts as the policy engine that enforces both MFA and IP-based restrictions at the authentication layer, not the network layer. On the Microsoft Cybersecurity Architect exam, this scenario tests your ability to distinguish between identity-centric controls (Conditional Access) and network-centric controls (NSGs, Azure Firewall), a common trap where candidates mistakenly choose network security groups or Azure Firewall for IP restrictions. Remember that App Service runs in a multitenant environment, so IP restrictions must be enforced through Conditional Access policies rather than traditional network security tools. A useful memory tip is "Auth + Policy, not Firewall or NSG" — authentication and conditional access handle user access, while network controls handle infrastructure traffic.

⚠ Common exam trap

SC-100 often tests the layering of identity vs. network controls — candidates pick NSG or Azure Firewall for IP restriction when the requirement is user-level access with MFA, which only Conditional Access can enforce.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Azure App Service authentication with Microsoft Entra ID

Option B is correct because configuring App Service authentication with Microsoft Entra ID (formerly Azure AD) enables the built-in Easy Auth middleware to authenticate users against the Entra ID identity provider, satisfying the requirement to use Microsoft Entra ID for authentication. Option C is correct because a Conditional Access policy in Microsoft Entra ID can enforce MFA for all users and apply named locations or IP-based conditions to restrict access to specific IP ranges, meeting both the MFA and IP restriction requirements at the identity layer. Option A is not correct because an NSG applied to the App Service subnet only filters network traffic by IP/port at the network layer and does not provide Microsoft Entra ID authentication or MFA. Option D is not correct because Azure Firewall filters inbound/outbound traffic but does not perform user authentication or MFA enforcement. Option E is not correct because registering the application in Microsoft Entra ID only creates the identity object/service principal; it does not by itself enable authentication, IP restrictions, or MFA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply a network security group (NSG) to the App Service subnet

    Why it's wrong here

    Network security groups are for virtual networks, not for App Service access control. They do not handle authentication or MFA requirements.

  • ✓

    Configure Azure App Service authentication with Microsoft Entra ID

    Why this is correct

    Azure App Service authentication can be configured to use Microsoft Entra ID, which is required for user authentication.

  • ✓

    Create a Conditional Access policy in Microsoft Entra ID that requires MFA and restricts IP ranges

    Why this is correct

    Conditional Access policies in Microsoft Entra ID can enforce MFA and restrict IP ranges, meeting the requirements.

  • ✗

    Deploy Azure Firewall to filter inbound traffic

    Why it's wrong here

    Azure Firewall is for network traffic filtering, not for user authentication or MFA enforcement.

  • ✗

    Register the application in Microsoft Entra ID

    Why it's wrong here

    Registering the application in Microsoft Entra ID is part of the setup but not a direct component for enforcing MFA and IP restrictions.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization, Adatum, is migrating its on-premises applications to Azure. The applications include a legacy .NET Framework web app that uses Windows authentication and a modern ASP.NET Core API that uses OAuth 2.0. You need to design a secure solution for these applications using Azure App Service. The security requirements include: (1) enforce HTTPS only, (2) restrict access to the web app based on the user's corporate identity, (3) allow the API to access an Azure SQL Database using a managed identity. Which of the following is the correct design?

easy
  • A.Configure the web app to use Windows authentication via Azure AD Domain Services, and the API to use SQL authentication with a managed identity.
  • B.Configure the web app to use Microsoft Entra ID authentication with a built-in policy, and the API to use a connection string with a username and password.
  • C.Configure the web app to require client certificates for authentication, and the API to use a connection string with SQL authentication.
  • ✓ D.Configure both apps to enforce HTTPS only, configure the web app to use Microsoft Entra ID authentication, and configure the API to use a system-assigned managed identity to access Azure SQL Database.

Why D: Option D is correct because it satisfies all three requirements: enabling HTTPS-only on both apps enforces TLS, configuring the web app with Microsoft Entra ID authentication restricts access based on corporate identity, and using a system-assigned managed identity lets the API authenticate to Azure SQL Database without storing credentials. Managed identity works with Azure SQL via Entra ID authentication, so no password is needed in the connection string. Option A is wrong because Azure AD Domain Services-based Windows authentication is not the recommended App Service approach and SQL authentication with a managed identity is contradictory. Option B is wrong because a username/password connection string does not use managed identity. Option C is wrong because client certificates do not provide corporate identity-based access and SQL authentication does not meet the managed identity requirement.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.