Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDMedium

A company is using Microsoft Entra ID to manage identities and has deployed Microsoft Entra Connect to synchronize users from their on-premises Active Directory. They want to implement a Conditional Access policy that requires multi-factor authentication (MFA) *only* when users sign in from outside the corporate network. All sign-ins originating from the company's main office IP ranges should not prompt for MFA. You need to configure this Conditional Access policy. What should you define in the policy's conditions?

  1. AUser risk policy set to 'High'
  2. BNamed locations excluding the corporate network
  3. CDevice state set to 'Not compliant'
  4. DSign-in risk policy set to 'Medium'
Show answer & explanation

Correct answer: B. Named locations excluding the corporate network

To require MFA only when users sign in from outside the corporate network, you should define 'Named locations' in the Conditional Access policy. By excluding the corporate network's IP ranges from the named locations, you can target the MFA requirement specifically for sign-ins originating from 'Any location' *excluding* those trusted corporate ranges.

Why the other options are wrong

  • A. User risk policies are based on unusual user behavior, not the network location of the sign-in.
  • C. Device state refers to whether a device meets compliance requirements, not the network location.
  • D. Sign-in risk policies are based on the probability of a sign-in being compromised, not the absence of a trusted network location.

Microsoft Entra Conditional Access Named Locations

A feature in Microsoft Entra Conditional Access that allows administrators to create logical groupings of IP address ranges (trusted or untrusted) which can then be used as conditions in Conditional Access policies.

  • Used to define trusted IP ranges for corporate networks.
  • Can be configured to exclude MFA or other controls for trusted locations.
  • Can also define untrusted or risky locations.
  • Essential for location-based Conditional Access policies.

Memory trick: Named Locations: No MFA when in my Network.

More Implement and manage Microsoft Entra ID questions