Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Hard
An administrator is configuring a new Conditional Access policy to require multi-factor authentication (MFA) for all users accessing SharePoint Online from outside the corporate network. After creating the policy, the administrator tests it with their own account, which is a global administrator. The policy does not trigger MFA. What is the most likely reason for this behavior?
- AMFA is not enabled for the administrator's account.
- BGlobal Administrators are exempt from Conditional Access policies by default.
- CThe administrator's device is already marked as compliant.
- DThe policy was not assigned to the correct user group.
Show answer & explanationAnswer & explanation
Correct answer: B. Global Administrators are exempt from Conditional Access policies by default.
By default, Global Administrator accounts are excluded from Conditional Access policies to prevent accidental lockout. This is a crucial safety measure in Azure AD. To test such policies, a non-admin test account or a specific exclusion override is required.
Why the other options are wrong
- A. Even if MFA is not enabled, the policy should still *attempt* to trigger it, and then fail if not configured, rather than not triggering at all due to an exclusion.
- C. Device compliance is a condition, but the *exclusion* of Global Admins takes precedence over policy conditions.
- D. While possible, the most likely default behavior for a Global Admin is an exclusion from CA policies.
Conditional Access Policy Exclusions
Specific users, groups, or roles that are intentionally excluded from the scope of a Conditional Access policy, often as a safety measure to prevent administrative lockouts.
- Global Administrator role is often excluded by default from new CA policies.
- Exclusions take precedence over inclusions.
- Critical for maintaining access in case of misconfigured policies.
Memory trick: First exclude, then include, then conditions subdue.