Design security operations, identity, and compliance capabilities →easyMultiple ChoiceObjective-mapped
MFA Enforcement with Conditional Access Grant Control
Your organization needs to enforce multi-factor authentication (MFA) for all users accessing sensitive applications. You plan to use Microsoft Entra ID Conditional Access. Which grant control should you configure?
Quick Answer
The answer is to configure the "Require multi-factor authentication" grant control. This is the correct choice because MFA enforcement with Conditional Access grant control directly addresses the need to verify user identity through a second factor, such as a phone call or app notification, without introducing additional requirements like device compliance or authentication strength. On the Microsoft Cybersecurity Architect exam, this question tests your ability to match a straightforward security requirement to the simplest effective control, often appearing as a baseline scenario where the trap is overcomplicating the solution by selecting "Require authentication strength" or "Require compliant device." A strong memory tip is to remember that when the goal is purely to enforce MFA, the simplest grant control is the correct one—think "MFA first, complexity later."
⚠ Common exam trap
Test-takers frequently confuse 'Require authentication strength' (which is a newer, more specific control for phishing-resistant MFA) with the general 'Require multi-factor authentication' control, leading them to select the more complex option when the question simply asks for MFA enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require multi-factor authentication
The question specifies a requirement to enforce MFA for all users accessing sensitive applications. In Microsoft Entra ID Conditional Access, the 'Require multi-factor authentication' grant control directly enforces Azure AD MFA (e.g., via Microsoft Authenticator, OATH tokens, or SMS) as the primary authentication method. This is the simplest and most direct control to meet the stated goal of requiring MFA, without adding additional constraints like device compliance or authentication strength levels.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Require multi-factor authentication
Why this is correct
This grant control directly enforces MFA.
- ✗
Require authentication strength (e.g., phishing-resistant MFA)
Why it's wrong here
Authentication strength is a separate feature, not a direct grant control for MFA.
- ✗
Require device to be marked as compliant
Why it's wrong here
Device compliance is separate from MFA.
- ✗
Use app enforced restrictions
Why it's wrong here
App enforced restrictions are for session control.
Go deeper
Related to this question
About these practice questions
One of 208 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization needs to enforce multi-factor authentication (MFA) for all users accessing Microsoft Entra ID integrated applications. However, users in the finance department should be exempted from MFA when accessing a specific legacy financial app that does not support modern authentication. What should you design?
easy- A.Enable security defaults for all users
- B.Enable per-user MFA and exclude the finance department
- C.Use Microsoft Entra Identity Protection to require MFA based on risk
- ✓ D.Create a Conditional Access policy that requires MFA for all cloud apps except the legacy app
Why D: Conditional Access policies allow granular control over which applications require MFA. By creating a policy that requires MFA for all cloud apps except the legacy financial app, you can enforce MFA broadly while exempting the specific app that does not support modern authentication. This approach is more flexible and secure than per-user MFA or security defaults, as it can target specific applications and conditions.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.