SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your company is implementing a new application that requires users to authenticate using Microsoft Entra ID. The security team wants to enforce multifactor authentication (MFA) for all users accessing this application, but only when they are connecting from an untrusted network. Which conditional access policy should you configure?
⚠ Common exam trap
Many candidates confuse 'Grant control' with 'Session control' or overlook the need to exclude trusted locations, leading them to select an option that either enforces MFA everywhere or uses an inappropriate control like device compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant control: 'Require multifactor authentication' with a condition on 'Locations' set to 'All trusted locations' as exclusion.
It configures a Conditional Access policy that grants access only when MFA is performed, and excludes trusted network locations. This ensures that MFA is enforced only when users connect from untrusted networks, meeting the security team's requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Session control: 'Use app enforced restrictions' to block access from untrusted networks.
Why it's wrong here
Session controls, such as 'Use app enforced restrictions', are designed to monitor and control user actions *within* an established session, typically integrating with Microsoft Defender for Cloud Apps. They operate after initial authentication and are used for in-session restrictions like blocking downloads or restricting copy/paste. These controls do not prevent a user from authenticating from an untrusted network or enforce multifactor authentication as a prerequisite for access, making them unsuitable for blocking initial access based on network trust.
- ✓
Grant control: 'Require multifactor authentication' with a condition on 'Locations' set to 'All trusted locations' as exclusion.
Why this is correct
This configuration correctly addresses the requirement by leveraging Conditional Access's powerful location-based targeting. By setting the 'Locations' condition to 'Any location' and then explicitly *excluding* 'All trusted locations', the policy precisely targets only connections originating from untrusted networks. The 'Require multifactor authentication' grant control then ensures that users attempting to access the application from these untrusted networks must successfully complete an MFA challenge, significantly enhancing security for high-risk access attempts.
- ✗
Assignments: 'Users and groups' including all users, then grant control: 'Require multifactor authentication' without conditions.
Why it's wrong here
This policy configuration would enforce multifactor authentication for *all* users accessing the application, irrespective of their network location. While implementing MFA universally enhances overall security, it fails to meet the specific requirement of *only* targeting untrusted networks. Requiring MFA for users connecting from already secure, trusted corporate networks would introduce unnecessary friction and potentially degrade user experience without adding proportional security benefit for those trusted connections.
- ✗
Grant control: 'Require device to be marked as compliant' with a condition on 'Client apps'.
Why it's wrong here
The 'Require device to be marked as compliant' grant control focuses on the security posture and health of the accessing device, ensuring it meets organizational standards (e.g., OS version, patch level, encryption status). This control does not evaluate or act upon the network location from which a user is connecting. It is solely concerned with the device's configuration, making it ineffective for blocking or restricting access specifically based on whether the network itself is considered untrusted. The 'Client apps' condition further refines which applications are targeted, but still doesn't address network trust.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.