A developer is configuring Azure AD Conditional Access policies for a critical application. The goal is to enforce multi-factor authentication (MFA) for users accessing the application from outside the corporate network, but allow single sign-on (SSO) for users within the corporate network. Which combination of conditions and access controls should be used?
- AConditions: Users/Groups, Cloud apps, Locations. Access controls: Grant access, Require MFA for 'Outside corporate network' location.
- BConditions: Users/Groups, Cloud apps, Device Platforms. Access controls: Grant access, Require MFA.
- CConditions: Users/Groups, Cloud apps, Sign-in risk. Access controls: Grant access, Require MFA for 'High risk' sign-ins.
- DConditions: Users/Groups, Client apps. Access controls: Grant access, Block access for 'Outside corporate network'.
Show answer & explanationAnswer & explanation
Correct answer: A. Conditions: Users/Groups, Cloud apps, Locations. Access controls: Grant access, Require MFA for 'Outside corporate network' location.
To enforce MFA based on network location, the Conditional Access policy needs to use 'Locations' as a condition. You would define a named location for your corporate network. The policy would then target users, the specific cloud app, and apply the 'Require MFA' control when the location condition evaluates to 'not in corporate network' (or 'any location' excluding the trusted one).
Why the other options are wrong
- B. Device Platforms are not directly used to distinguish between corporate and external networks for MFA enforcement.
- C. Sign-in risk is a valuable condition, but it's different from enforcing MFA based strictly on network location, which is the primary requirement here.
- D. Blocking access for 'Outside corporate network' is too restrictive; the goal is to *allow* access with MFA, not block it.
Azure AD Conditional Access Policy
An Azure AD feature that allows organizations to enforce policies (access controls) based on specific conditions (user, location, device, app, etc.) when users attempt to access cloud applications.
- Enables risk-based access decisions
- Supports MFA, device compliance, terms of use, etc.
- Uses 'conditions' and 'access controls' to define policies
Memory trick: Conditional Access: If you're 'out of bounds', you need extra ID.