You are designing a secure access strategy for Azure App Service web applications. The requirements are: use Azure AD for authentication, restrict access to specific IP ranges, and require multi-factor authentication (MFA) for all users. Which two components should you configure? (Choose two.)
Azure App Service authentication can be configured to use Microsoft Entra ID, which is required for user authentication.
Why this answer
Option B is correct because configuring App Service authentication with Microsoft Entra ID (formerly Azure AD) enables the built-in Easy Auth middleware to authenticate users against the Entra ID identity provider, satisfying the requirement to use Azure AD for authentication. Option C is correct because a Conditional Access policy in Microsoft Entra ID can enforce MFA for all users and apply named locations or IP-based conditions to restrict access to specific IP ranges, meeting both the MFA and IP restriction requirements at the identity layer. Option A is not correct because an NSG applied to the App Service subnet only filters network traffic by IP/port at the network layer and does not provide Azure AD authentication or MFA.
Option D is not correct because Azure Firewall filters inbound/outbound traffic but does not perform user authentication or MFA enforcement. Option E is not correct because registering the application in Microsoft Entra ID only creates the identity object/service principal; it does not by itself enable authentication, IP restrictions, or MFA.
Exam trap
SC-100 often tests the layering of identity vs. network controls — candidates pick NSG or Azure Firewall for IP restriction when the requirement is user-level access with MFA, which only Conditional Access can enforce.