SC-900 Describe the capabilities of Microsoft Entra Practice Question
You are the identity administrator for Contoso Ltd., a global company with over 10,000 employees. The company uses Microsoft Entra ID P2 and Microsoft Intune. Employees use both company-owned and personal devices. The security team requires that all access to corporate applications be protected with multifactor authentication (MFA). However, to minimize user friction, they want to exempt MFA for users who are on the corporate network and using compliant devices. Additionally, for users with privileged roles (e.g., Global Administrator), MFA must always be required regardless of location or device. You need to configure a Conditional Access policy to meet these requirements. Which of the following approaches should you take?
⚠ Common exam trap
A common mix-up: candidates think a single policy with exclusions can handle all users, forgetting that privileged roles require unconditional MFA, which necessitates a separate policy with no exclusions to override the more permissive exclusions applied to regular users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create two Conditional Access policies: Policy 1 targets all users except privileged roles, requires MFA, and excludes trusted locations and compliant devices. Policy 2 targets privileged roles and requires MFA with no exclusions.
It uses two separate Conditional Access policies to handle the two distinct user groups. Policy 1 targets all users except privileged roles, requires MFA, and excludes trusted locations and compliant devices, which satisfies the requirement to minimize friction for users on the corporate network with compliant devices. Policy 2 targets privileged roles and requires MFA with no exclusions, ensuring that Global Administrators and other privileged role members always must perform MFA regardless of location or device compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create two Conditional Access policies: Policy 1 targets all users except privileged roles, requires MFA, and excludes trusted locations and compliant devices. Policy 2 targets privileged roles and requires MFA with no exclusions.
Why this is correct
This solution correctly implements a layered security approach using two distinct Conditional Access policies. Policy 1 ensures that standard users require Multi-Factor Authentication (MFA) but allows for usability by excluding trusted locations and compliant devices. Policy 2 specifically targets privileged roles, enforcing MFA without any exclusions, thereby guaranteeing that these high-impact accounts always face the strongest authentication challenge, regardless of their location or device compliance status. This design effectively balances security for privileged identities with user experience for general users.
- ✗
Create one Conditional Access policy that targets all users and requires MFA. Create a second policy that targets privileged roles and excludes trusted locations.
Why it's wrong here
This approach is flawed because the second Conditional Access policy, which targets privileged roles and *excludes* trusted locations, would inadvertently allow privileged users to bypass MFA when accessing resources from those trusted locations. While the first policy generally requires MFA for all users, a specific exclusion in a policy targeting privileged roles would take precedence for that group under those conditions, directly violating the critical requirement to always enforce MFA for privileged accounts.
- ✗
Create one Conditional Access policy that targets all users, requires MFA, and excludes trusted locations and compliant devices. Do not create any additional policies.
Why it's wrong here
This single Conditional Access policy is insufficient because its exclusions for trusted locations and compliant devices would apply universally to all users, including privileged roles. Without a separate, more stringent policy specifically targeting privileged accounts, these high-impact users would be able to bypass Multi-Factor Authentication if they are accessing resources from a trusted location or using a device deemed compliant. This creates an unacceptable security vulnerability for critical administrative functions.
- ✗
Create one Conditional Access policy that targets all users and requires MFA. Use Microsoft Intune compliance policies to exempt compliant devices from MFA.
Why it's wrong here
This option demonstrates a misunderstanding of the distinct roles of Microsoft Intune compliance policies and Azure AD Conditional Access. Intune compliance policies define the health and configuration standards for devices, reporting their compliance status to Azure AD. However, Intune policies do not directly control or exempt Multi-Factor Authentication. Conditional Access policies are the sole mechanism within Azure AD for enforcing MFA requirements or granting exemptions based on conditions, including the device compliance status determined by Intune.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.