Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Easy

A Microsoft 365 Endpoint Administrator wants to ensure that users can only access corporate resources from specific IP ranges within the company's network. If a user attempts to access resources from outside these IP ranges, access should be blocked. Which Conditional Access condition should be configured?

  1. ASign-in risk
  2. BLocations
  3. CUser risk
  4. DDevice platforms
Show answer & explanation

Correct answer: B. Locations

The 'Locations' condition in Conditional Access policies allows administrators to define trusted IP ranges (named locations) and then either include or exclude them from policy application, directly addressing the need to restrict access based on network location.

Why the other options are wrong

  • A. Sign-in risk evaluates the risk associated with a specific sign-in attempt, not the static network location.
  • C. User risk assesses the likelihood of a user's identity being compromised, not their network location.
  • D. Device platforms condition targets specific operating systems (e.g., Windows, iOS), not network location.

Conditional Access: Locations Condition

A condition in Conditional Access policies that allows defining trusted or untrusted network locations (IP ranges, countries) to control access to resources.

  • Uses named locations (IP ranges).
  • Can include or exclude specific locations.
  • Essential for geographically restricted access.

Memory trick: Locations condition is the bouncer checking where you're coming from.

More Manage identity and compliance (10-15%) questions