Courseiva

SC-100 Conditional Access Practice Question

Your organization uses Microsoft Entra ID. You need to design a solution that requires users to perform multifactor authentication when accessing a critical application from an untrusted network. The solution should not require additional licensing beyond Microsoft Entra ID P1. What should you use?

⚠ Common exam trap

The trap is that candidates might choose Microsoft Entra ID Protection (P2) because it seems more sophisticated, but the requirement is no additional licensing beyond P1, so Conditional Access with location condition is sufficient and included. Also candidates might confuse per-user MFA with Conditional Access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Conditional Access policy in Microsoft Entra ID.

Create a Conditional Access policy in Microsoft Entra ID. Conditional Access is included with Microsoft Entra ID P1 and lets you enforce MFA specifically when users access a chosen cloud app from an untrusted network location, using conditions such as the application and named locations plus a grant control requiring multifactor authentication. Option B is not the best fit because risk-based sign-in/user risk policies require Microsoft Entra ID P2 (Entra ID Protection), exceeding the stated P1 licensing limit. Option C, per-user MFA, can require MFA but is an all-or-nothing setting that cannot target a specific application or network condition. Option D, an Intune device compliance policy, addresses device configuration and compliance rather than directly enforcing MFA for app access from untrusted networks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a Conditional Access policy in Microsoft Entra ID.

    Why this is correct

    A Conditional Access policy is the modern, context-aware mechanism in Microsoft Entra ID for enforcing MFA. It can precisely target specified users, groups, or applications, and evaluate conditions such as geographic location (via named locations), trusted IPs, device state, and sign-in risk. Because Conditional Access is included with Entra ID P1, it directly satisfies the requirement to enforce MFA based on location without requiring any additional licensing.

  • ✗

    Configure a risk-based policy in Microsoft Entra ID Protection.

    Why it's wrong here

    Microsoft Entra ID Protection offers risk-based policies that can, for example, require MFA when sign-in risk is deemed medium or high, and these policies can also factor in location anomalies. However, leveraging ID Protection for such policies requires Microsoft Entra ID P2 licensing, which the organization does not have. Furthermore, risk policies are fundamentally designed to respond to identity-related risk signals, not to serve as a direct, location-specific MFA enforcement mechanism.

  • ✗

    Enable per-user MFA in Microsoft Entra ID.

    Why it's wrong here

    Per-user MFA is a legacy method that simply forces MFA for every sign-in of the configured user, providing no ability to conditionally apply MFA based on network location or other contextual signals. This approach is highly inflexible and can cause unnecessary authentication friction for users already on trusted networks. In modern Microsoft Entra ID, Microsoft recommends retiring per-user MFA in favor of Conditional Access policies, which offer granular control and are fully supported for location-based enforcement.

  • ✗

    Deploy a device compliance policy in Microsoft Intune.

    Why it's wrong here

    Intune device compliance policies assess whether managed devices meet policies such as required OS versions, disk encryption, or threat defense status, but they do not inherently trigger MFA challenges based on network location. To use Intune, you must have separate Intune or Microsoft 365 E5 licensing, which goes beyond the existing Entra ID P1. Such compliance policies are typically used as a condition within a Conditional Access policy, not as a standalone alternative for location-based MFA enforcement.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.