Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantEasy

A Microsoft 365 administrator is planning to implement multi-factor authentication (MFA) for all users in the tenant. They want to ensure that users are prompted for MFA when accessing Microsoft 365 services from outside the corporate network, but not when they are on the trusted corporate network. Which Azure AD feature should the administrator use to achieve this requirement?

  1. AAzure AD PIM
  2. BSecurity Defaults
  3. CAzure AD Identity Protection
  4. DAzure AD Conditional Access
Show answer & explanation

Correct answer: D. Azure AD Conditional Access

Azure AD Conditional Access allows administrators to define policies based on conditions such as network location. By configuring a Conditional Access policy, the administrator can require MFA when users are outside the corporate network (an untrusted location) and bypass it when they are on the trusted corporate network.

Why the other options are wrong

  • A. PIM manages just-in-time access for privileged roles, not general MFA enforcement based on network location.
  • B. Security Defaults enforce MFA for all sign-ins, without granular control for trusted locations.
  • C. Identity Protection detects risks, but Conditional Access is used to enforce policies based on those risks or other conditions like location.

Conditional Access for MFA

Azure AD Conditional Access policies can be configured to enforce Multi-Factor Authentication (MFA) based on specific conditions, such as user location (trusted vs. untrusted networks), device state, or application being accessed. This allows for flexible and risk-based MFA enforcement.

  • Requires Azure AD Premium P1 or P2 license (included in Microsoft 365 E3/E5).
  • Allows defining trusted network locations (named locations).
  • Can enforce MFA for specific users, apps, and conditions.
  • Provides a more granular control over MFA than Security Defaults.

Memory trick: Location-based MFA: Conditional Access makes the call.

More Deploy and manage a Microsoft 365 tenant questions