Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDHard
A company is using Microsoft Entra ID for identity management and has deployed Microsoft Entra Connect to synchronize users from their on-premises Active Directory. The security team has identified a need to enforce Multi-Factor Authentication (MFA) for all users accessing sensitive cloud applications, but only when they are outside the corporate network. Users should not be prompted for MFA when connecting from trusted corporate IP ranges. Which Microsoft Entra feature should you configure?
- ANamed locations in Conditional Access
- BMFA registration policy
- CSelf-service password reset (SSPR) policy
- DMicrosoft Entra ID Protection sign-in risk policy
Show answer & explanationAnswer & explanation
Correct answer: A. Named locations in Conditional Access
Named locations in Conditional Access allow you to define trusted IP ranges (e.g., corporate network). You can then create a Conditional Access policy that requires MFA for sensitive applications but excludes users coming from these named locations, fulfilling the requirement.
Why the other options are wrong
- B. MFA registration policy enforces MFA setup, not conditional enforcement based on network location for specific apps.
- C. SSPR policy manages password reset capabilities, unrelated to conditional MFA enforcement.
- D. ID Protection sign-in risk policies can trigger MFA, but they are primarily based on risk levels, not solely on network location for every sensitive app access.
Conditional Access Named Locations
A feature in Microsoft Entra Conditional Access that allows administrators to define trusted IP address ranges or countries/regions.
- Used in Conditional Access policies to include or exclude users based on their network origin.
- Can mark IP ranges as 'trusted' to reduce MFA prompts.
- Enhances security by enforcing stricter controls for connections from untrusted locations.
Memory trick: Location Matters for Access Control.