Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDMedium

A company is using Microsoft Entra ID to manage identities and has deployed Microsoft Entra Connect to synchronize users from its on-premises Active Directory. They have a specific requirement to ensure that users can only access sensitive cloud applications when they are physically present in one of the company's designated office locations. Access from any other location, including remote work or personal networks, should be blocked. Which Microsoft Entra Conditional Access component should be configured to enforce this policy?

  1. AUser risk condition
  2. BNamed locations condition
  3. CDevice state condition
  4. DClient apps condition
Show answer & explanation

Correct answer: B. Named locations condition

Microsoft Entra Conditional Access 'Named locations' allow administrators to define trusted IP address ranges (e.g., company office networks). By configuring a policy to include these named locations and block access from 'Any location' excluding the named ones, the requirement can be met.

Why the other options are wrong

  • A. User risk condition evaluates the aggregate risk level of a user based on past activities, not their current sign-in location.
  • C. Device state condition checks if a device is compliant or hybrid Azure AD joined, not its physical network location.
  • D. Client apps condition targets specific application types (e.g., browser, mobile apps), not the source network.

Microsoft Entra Conditional Access Named Locations

Microsoft Entra Conditional Access Named locations are custom IP address ranges or countries/regions that can be defined in Microsoft Entra ID. These locations can then be used as conditions in Conditional Access policies to grant or block access based on a user's network origin.

  • Defines trusted or untrusted IP ranges/countries.
  • Used as a condition in Conditional Access policies.
  • Crucial for location-based access control.

Memory trick: Conditions: What's the Context?

More Implement and manage Microsoft Entra ID questions