Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium

A company is configuring an Azure AD Conditional Access policy to enforce multi-factor authentication (MFA) for all users accessing a specific sensitive application. The company wants to ensure that users who are already MFA-compliant from their trusted corporate network are not prompted again. Which condition should be configured in the Conditional Access policy to achieve this goal?

  1. AClient apps
  2. BFilter for devices
  3. CSign-in risk
  4. DLocations
Show answer & explanation

Correct answer: D. Locations

The 'Locations' condition in Conditional Access policies allows administrators to specify trusted IP ranges (named locations). By excluding these named locations from the MFA requirement, users accessing the sensitive application from the trusted corporate network will not be prompted for MFA, fulfilling the company's requirement.

Why the other options are wrong

  • A. Client apps condition allows targeting specific application types (e.g., browser, mobile apps), not the network location of the user.
  • B. Filter for devices allows targeting or excluding specific device attributes, not network locations.
  • C. Sign-in risk assesses the likelihood of a suspicious sign-in, not the user's network location.

Conditional Access Locations

A Conditional Access policy condition that allows administrators to specify network locations (e.g., trusted IP ranges) to include or exclude from policy enforcement.

  • Uses 'Named locations' defined in Azure AD.
  • Can be used to enforce or bypass MFA based on network.
  • Crucial for balancing security and user experience.

Memory trick: Conditions Control Access Decisions.

More Implement an authentication and access management solution questions