Courseiva
Describe the capabilities of Microsoft EntramediumMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Your company is implementing a new application that requires users to authenticate using Microsoft Entra ID. The security team wants to enforce multifactor authentication (MFA) for all users accessing this application, but only when they are connecting from an untrusted network. Which conditional access policy should you configure?

⚠ Common exam trap

Many candidates confuse 'Grant control' with 'Session control' or overlook the need to exclude trusted locations, leading them to select an option that either enforces MFA everywhere or uses an inappropriate control like device compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Grant control: 'Require multifactor authentication' with a condition on 'Locations' set to 'All trusted locations' as exclusion.

It configures a Conditional Access policy that grants access only when MFA is performed, and excludes trusted network locations. This ensures that MFA is enforced only when users connect from untrusted networks, meeting the security team's requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Session control: 'Use app enforced restrictions' to block access from untrusted networks.

    Why it's wrong here

    Session controls, such as 'Use app enforced restrictions', are designed to monitor and control user actions *within* an established session, typically integrating with Microsoft Defender for Cloud Apps. They operate after initial authentication and are used for in-session restrictions like blocking downloads or restricting copy/paste. These controls do not prevent a user from authenticating from an untrusted network or enforce multifactor authentication as a prerequisite for access, making them unsuitable for blocking initial access based on network trust.

  • Grant control: 'Require multifactor authentication' with a condition on 'Locations' set to 'All trusted locations' as exclusion.

    Why this is correct

    This configuration correctly addresses the requirement by leveraging Conditional Access's powerful location-based targeting. By setting the 'Locations' condition to 'Any location' and then explicitly *excluding* 'All trusted locations', the policy precisely targets only connections originating from untrusted networks. The 'Require multifactor authentication' grant control then ensures that users attempting to access the application from these untrusted networks must successfully complete an MFA challenge, significantly enhancing security for high-risk access attempts.

  • Assignments: 'Users and groups' including all users, then grant control: 'Require multifactor authentication' without conditions.

    Why it's wrong here

    This policy configuration would enforce multifactor authentication for *all* users accessing the application, irrespective of their network location. While implementing MFA universally enhances overall security, it fails to meet the specific requirement of *only* targeting untrusted networks. Requiring MFA for users connecting from already secure, trusted corporate networks would introduce unnecessary friction and potentially degrade user experience without adding proportional security benefit for those trusted connections.

  • Grant control: 'Require device to be marked as compliant' with a condition on 'Client apps'.

    Why it's wrong here

    The 'Require device to be marked as compliant' grant control focuses on the security posture and health of the accessing device, ensuring it meets organizational standards (e.g., OS version, patch level, encryption status). This control does not evaluate or act upon the network location from which a user is connecting. It is solely concerned with the device's configuration, making it ineffective for blocking or restricting access specifically based on whether the network itself is considered untrusted. The 'Client apps' condition further refines which applications are targeted, but still doesn't address network trust.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.