Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionEasy

A company uses Azure Active Directory (Azure AD) and has implemented Conditional Access policies. A new policy is being designed to require multifactor authentication (MFA) for all users accessing sensitive applications, but only when they are outside a trusted network location. How should this Conditional Access policy be configured?

  1. ASet 'Users and groups' to 'All users', 'Cloud apps or actions' to 'Selected apps', 'Conditions' to 'Locations' including trusted locations, and 'Grant' to 'Block access'.
  2. BSet 'Users and groups' to 'All users', 'Cloud apps or actions' to 'All cloud apps', 'Conditions' to 'Locations' including trusted locations, and 'Grant' to 'Require multifactor authentication'.
  3. CSet 'Users and groups' to 'Selected users', 'Cloud apps or actions' to 'Selected apps', 'Conditions' to 'Device platforms' for all platforms, and 'Grant' to 'Require multifactor authentication'.
  4. DSet 'Users and groups' to 'All users', 'Cloud apps or actions' to 'Selected apps', 'Conditions' to 'Locations' excluding trusted locations, and 'Grant' to 'Require multifactor authentication'.
Show answer & explanation

Correct answer: D. Set 'Users and groups' to 'All users', 'Cloud apps or actions' to 'Selected apps', 'Conditions' to 'Locations' excluding trusted locations, and 'Grant' to 'Require multifactor authentication'.

To meet the requirements, the policy must target all users and the sensitive applications. The key condition is to apply MFA *only when outside a trusted network*, which is achieved by configuring 'Locations' to 'Exclude' the defined trusted locations. Finally, the 'Grant' control must be set to 'Require multifactor authentication'.

Why the other options are wrong

  • A. This option 'Blocks access' instead of requiring MFA and incorrectly 'includes' trusted locations.
  • B. This option incorrectly targets 'All cloud apps' and 'includes' trusted locations, which would require MFA from *inside* trusted locations.
  • C. This option targets 'Selected users' and 'Device platforms' instead of 'Locations', not meeting the network location requirement.

Conditional Access Policy Structure

Azure AD Conditional Access policies define 'If-Then' statements: 'If' conditions are met, 'then' enforce access controls.

  • Composed of Assignments (Users, Cloud apps) and Access Controls (Grant, Session).
  • Conditions (Locations, Device platforms, Client apps, Sign-in risk) refine policy applicability.
  • Policies are processed after authentication and before resource access.

Memory trick: 🚦 If conditions match, 🔐 then control access.

More Implement an authentication and access management solution questions