A company uses Azure Active Directory (Azure AD) and has implemented several Conditional Access policies. One specific policy is configured to require multi-factor authentication (MFA) for all users accessing cloud apps, but it excludes users from a trusted IP range. Another policy requires compliant devices for users accessing a specific finance application. A user attempts to access the finance application from a non-compliant device, but they are within the trusted IP range. Which action will Azure AD take?
- AThe user will be blocked from accessing the finance application.
- BThe user will be granted access to the finance application without any additional prompts.
- CThe user will be prompted to register their device as compliant before being granted access.
- DThe user will be prompted for multi-factor authentication and then granted access if MFA is successful.
Show answer & explanationAnswer & explanation
Correct answer: A. The user will be blocked from accessing the finance application.
Conditional Access policies are evaluated sequentially, but if multiple policies apply, the most restrictive outcome is enforced. In this scenario, one policy requires MFA but has an exclusion for trusted IPs, which the user satisfies. However, another policy explicitly requires a compliant device for the finance app, and the user's device is non-compliant. Since 'Block access' is more restrictive than 'Grant access' (even with MFA), the user will be blocked.
Why the other options are wrong
- B. This is incorrect as the device compliance policy explicitly blocks non-compliant devices for the finance application.
- C. Azure AD Conditional Access does not automatically prompt for device registration in this blocking scenario; it enforces the configured access controls.
- D. This would be the outcome if only the MFA policy applied and the device compliance policy was not configured or did not apply.
Conditional Access Policy Enforcement
When multiple Conditional Access policies apply to a user and resource, Azure AD enforces the most restrictive outcome among all applicable policies.
- Policies are evaluated sequentially.
- If multiple policies apply, the most restrictive control is enforced.
- 'Block access' is generally the most restrictive outcome.
- Exclusions in one policy do not override requirements in another applicable policy if the latter is more restrictive.
Memory trick: When facing multiple traffic lights, the one saying 'STOP' always wins, even if others say 'GO'.